File name:

TNod-1.7.0-Beta-Portable.rar

Full analysis: https://app.any.run/tasks/e292695e-70be-4118-9608-51773ca467f9
Verdict: Malicious activity
Analysis date: August 03, 2020, 09:08:42
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

894D374879932C2A4C60C923EE4C3C5E

SHA1:

9ACA44A80E0C73B63EDC99B82DD4E35DB66628A1

SHA256:

A70B79F6FA89A35C7F84E37CC5C80B2B98E356E7B5646B08D476F1C92180BFB4

SSDEEP:

24576:unlfTh8m9DL9t/euj7S6NoqLUUCwth7VnhLuvEBdfDf7PRyygP+/N7KP6NS5QIdZ:utt/tb7SiC679hMEBdfZb/NuP2Hwb

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads Internet Cache Settings

      • TNODUP-Portable.exe (PID: 2340)
      • TNODUP-Portable.exe (PID: 2140)
      • TNODUP-Portable.exe (PID: 3528)
  • INFO

    • Manual execution by user

      • cmd.exe (PID: 488)
      • TNODUP-Portable.exe (PID: 2140)
      • cmd.exe (PID: 2428)
      • cmd.exe (PID: 2704)
      • cmd.exe (PID: 2292)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 117
UncompressedSize: 24
OperatingSystem: Win32
ModifyDate: 2012:05:29 00:03:28
PackingMethod: Normal
ArchivedFileName: TNod-1.7.0-Beta-Portable\Config.bat
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
53
Monitored processes
10
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs tnodup-portable.exe cmd.exe no specs tnodup-portable.exe cmd.exe no specs tnodup-portable.exe no specs cmd.exe no specs tnodup-portable.exe cmd.exe no specs tnodup-portable.exe

Process information

PID
CMD
Path
Indicators
Parent process
488cmd /c ""C:\Users\admin\Desktop\TNod-1.7.0-Beta-Portable\Licenses Downloader.bat" "C:\Windows\system32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2140"C:\Users\admin\Desktop\TNod-1.7.0-Beta-Portable\TNODUP-Portable.exe" C:\Users\admin\Desktop\TNod-1.7.0-Beta-Portable\TNODUP-Portable.exe
explorer.exe
User:
admin
Company:
Tukero[X]Team
Integrity Level:
MEDIUM
Description:
TNod User & Password Finder
Exit code:
0
Version:
,
Modules
Images
c:\users\admin\desktop\tnod-1.7.0-beta-portable\tnodup-portable.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2292cmd /c ""C:\Users\admin\Desktop\TNod-1.7.0-Beta-Portable\Recover current License.bat" "C:\Windows\system32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2340TNODUP-Portable /lC:\Users\admin\Desktop\TNod-1.7.0-Beta-Portable\TNODUP-Portable.exe
cmd.exe
User:
admin
Company:
Tukero[X]Team
Integrity Level:
MEDIUM
Description:
TNod User & Password Finder
Exit code:
0
Version:
,
Modules
Images
c:\users\admin\desktop\tnod-1.7.0-beta-portable\tnodup-portable.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2416"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\TNod-1.7.0-Beta-Portable.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2428cmd /c ""C:\Users\admin\Desktop\TNod-1.7.0-Beta-Portable\Insert License with the maximum expiration date.bat" "C:\Windows\system32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2704cmd /c ""C:\Users\admin\Desktop\TNod-1.7.0-Beta-Portable\Config.bat" "C:\Windows\system32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2820TNODUP-Portable /bC:\Users\admin\Desktop\TNod-1.7.0-Beta-Portable\TNODUP-Portable.execmd.exe
User:
admin
Company:
Tukero[X]Team
Integrity Level:
MEDIUM
Description:
TNod User & Password Finder
Exit code:
0
Version:
,
Modules
Images
c:\users\admin\desktop\tnod-1.7.0-beta-portable\tnodup-portable.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
3528TNODUP-Portable /o /xC:\Users\admin\Desktop\TNod-1.7.0-Beta-Portable\TNODUP-Portable.exe
cmd.exe
User:
admin
Company:
Tukero[X]Team
Integrity Level:
MEDIUM
Description:
TNod User & Password Finder
Exit code:
0
Version:
,
Modules
Images
c:\users\admin\desktop\tnod-1.7.0-beta-portable\tnodup-portable.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
3952TNODUP-Portable /sC:\Users\admin\Desktop\TNod-1.7.0-Beta-Portable\TNODUP-Portable.exe
cmd.exe
User:
admin
Company:
Tukero[X]Team
Integrity Level:
MEDIUM
Description:
TNod User & Password Finder
Exit code:
0
Version:
,
Modules
Images
c:\users\admin\desktop\tnod-1.7.0-beta-portable\tnodup-portable.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
Total events
528
Read events
507
Write events
21
Delete events
0

Modification events

(PID) Process:(2416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2416) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\132\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\TNod-1.7.0-Beta-Portable.rar
(PID) Process:(2416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(2416) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(2140) TNODUP-Portable.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
Executable files
0
Suspicious files
0
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
2416WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2416.7558\TNod-1.7.0-Beta-Portable\Config.bat
MD5:
SHA256:
2416WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2416.7558\TNod-1.7.0-Beta-Portable\Insert License with the maximum expiration date.bat
MD5:
SHA256:
2416WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2416.7558\TNod-1.7.0-Beta-Portable\Licenses Downloader.bat
MD5:
SHA256:
2416WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2416.7558\TNod-1.7.0-Beta-Portable\Recover current License.bat
MD5:
SHA256:
2416WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2416.7558\TNod-1.7.0-Beta-Portable\TNODUP-Portable.exe
MD5:
SHA256:
2416WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb2416.7558\TNod-1.7.0-Beta-Portable\TNODUP-Portable.ini
MD5:
SHA256:
2140TNODUP-Portable.exeC:\Users\admin\Desktop\TNod-1.7.0-Beta-Portable\TNODUP-Portable.initext
MD5:
SHA256:
3528TNODUP-Portable.exeC:\Users\admin\Desktop\TNod-1.7.0-Beta-Portable\TNODUP-Portable.initext
MD5:
SHA256:
3952TNODUP-Portable.exeC:\Users\admin\Desktop\TNod-1.7.0-Beta-Portable\TNODUP-Portable.initext
MD5:
SHA256:
2340TNODUP-Portable.exeC:\Users\admin\Desktop\TNod-1.7.0-Beta-Portable\TNODUP-Portable.initext
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
48
DNS requests
9
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2140
TNODUP-Portable.exe
GET
200
91.228.165.81:80
http://iploc.eset.com/ip_locate_iso2
SK
xml
247 b
whitelisted
2340
TNODUP-Portable.exe
GET
200
91.228.165.81:80
http://iploc.eset.com/ip_locate_iso2
SK
xml
247 b
whitelisted
2340
TNODUP-Portable.exe
GET
302
216.58.213.179:80
http://shorturls.tukero.org/tnodserver
US
malicious
2340
TNODUP-Portable.exe
GET
216.58.213.65:80
http://tnoduse2.blogspot.com/
US
whitelisted
2340
TNODUP-Portable.exe
GET
200
216.58.213.65:80
http://tnoduse2.blogspot.com/feeds/posts/default?alt=rss
US
xml
1.77 Kb
whitelisted
3952
TNODUP-Portable.exe
GET
200
91.228.165.81:80
http://iploc.eset.com/ip_locate_iso2
SK
xml
247 b
whitelisted
3528
TNODUP-Portable.exe
GET
200
91.228.165.81:80
http://iploc.eset.com/ip_locate_iso2
SK
xml
247 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2140
TNODUP-Portable.exe
91.228.165.81:80
iploc.eset.com
ESET, spol. s r.o.
SK
unknown
2340
TNODUP-Portable.exe
91.228.165.81:80
iploc.eset.com
ESET, spol. s r.o.
SK
unknown
2340
TNODUP-Portable.exe
216.58.213.179:80
shorturls.tukero.org
Google Inc.
US
unknown
2340
TNODUP-Portable.exe
216.58.213.65:80
tnoduse2.blogspot.com
Google Inc.
US
unknown
2340
TNODUP-Portable.exe
116.203.50.155:443
de.hideproxy.me
334,Udyog Vihar
IN
unknown
2340
TNODUP-Portable.exe
13.64.117.133:443
edf.eset.com
Microsoft Corporation
US
whitelisted
3528
TNODUP-Portable.exe
91.228.165.81:80
iploc.eset.com
ESET, spol. s r.o.
SK
unknown
3952
TNODUP-Portable.exe
91.228.165.81:80
iploc.eset.com
ESET, spol. s r.o.
SK
unknown

DNS requests

Domain
IP
Reputation
iploc.eset.com
  • 91.228.165.81
whitelisted
shorturls.tukero.org
  • 216.58.213.179
malicious
tnoduse2.blogspot.com
  • 216.58.213.65
whitelisted
de.hideproxy.me
  • 116.203.50.155
unknown
edf.eset.com
  • 13.64.117.133
unknown

Threats

No threats detected
No debug info