File name:

【★】CapMonster v2.10.16.0 +SQLiDumper_10.2_Cracked_By_Angeal【★】.rar

Full analysis: https://app.any.run/tasks/9a862f4e-8f8d-4d7e-a4d0-9eeb44bd8698
Verdict: Malicious activity
Analysis date: July 02, 2020, 07:25:21
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
evasion
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

FD819900C09C1779AFA2F9613816DF2E

SHA1:

E3FFDB0842FF9BEA1D9A5B6A14A451681BA1BEE3

SHA256:

A7BDB69DF5D4B64E8EE10EF1C8617E938C401219B7269B2F09B731A117612543

SSDEEP:

196608:MaNZymrclHQBTPOx+7yCdj+kGfWCN1qSSSTI+jhGMVGh:JNZ7rWwROs7yC9G//qSSOIMoh

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • 3CKPI0YR2.0.EXE (PID: 3624)
    • Writes to a start menu file

      • 3CKPI0YR2.0.EXE (PID: 3624)
    • Application was dropped or rewritten from another process

      • 3CKPI0YR2.0.EXE (PID: 3624)
      • SQLI DUMPER_CRACKED_BY_ANGEAL.EXE (PID: 1776)
    • Loads dropped or rewritten executable

      • SQLI DUMPER_CRACKED_BY_ANGEAL.EXE (PID: 1776)
      • SearchProtocolHost.exe (PID: 3440)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • SQLI DUMPER_CRACKED_BY_ANGEAL.EXE (PID: 1776)
      • SQLi Dumper_Cracked_By_Angeal.exe (PID: 2056)
    • Creates files in the user directory

      • 3CKPI0YR2.0.EXE (PID: 3624)
    • Reads Environment values

      • SQLI DUMPER_CRACKED_BY_ANGEAL.EXE (PID: 1776)
    • Checks for external IP

      • SQLI DUMPER_CRACKED_BY_ANGEAL.EXE (PID: 1776)
  • INFO

    • Manual execution by user

      • SQLi Dumper_Cracked_By_Angeal.exe (PID: 2056)
    • Dropped object may contain Bitcoin addresses

      • SQLi Dumper_Cracked_By_Angeal.exe (PID: 2056)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
5
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start drop and start drop and start winrar.exe no specs sqli dumper_cracked_by_angeal.exe 3ckpi0yr2.0.exe sqli dumper_cracked_by_angeal.exe searchprotocolhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1776"C:\Users\admin\AppData\Local\Temp\SQLI DUMPER_CRACKED_BY_ANGEAL.EXE" C:\Users\admin\AppData\Local\Temp\SQLI DUMPER_CRACKED_BY_ANGEAL.EXE
SQLi Dumper_Cracked_By_Angeal.exe
User:
admin
Company:
fLaSh
Integrity Level:
MEDIUM
Description:
SQLi Dumper
Exit code:
0
Version:
10.2.0.0
Modules
Images
c:\users\admin\appdata\local\temp\sqli dumper_cracked_by_angeal.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2056"C:\Users\admin\Desktop\【★】CapMonster v2.10.16.0 +SQLiDumper_10.2_Cracked_By_Angeal【★】\SQLiDumper_10.2_Cracked_By_Angeal_Cleaned_FullyPatched\SQLi Dumper_Cracked_By_Angeal.exe" C:\Users\admin\Desktop\【★】CapMonster v2.10.16.0 +SQLiDumper_10.2_Cracked_By_Angeal【★】\SQLiDumper_10.2_Cracked_By_Angeal_Cleaned_FullyPatched\SQLi Dumper_Cracked_By_Angeal.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\desktop\【★】capmonster v2.10.16.0 +sqlidumper_10.2_cracked_by_angeal【★】\sqlidumper_10.2_cracked_by_angeal_cleaned_fullypatched\sqli dumper_cracked_by_angeal.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2804"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\【★】CapMonster v2.10.16.0 +SQLiDumper_10.2_Cracked_By_Angeal【★】.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3440"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3624"C:\Users\admin\AppData\Local\Temp\3CKPI0YR2.0.EXE" C:\Users\admin\AppData\Local\Temp\3CKPI0YR2.0.EXE
SQLi Dumper_Cracked_By_Angeal.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Get Cliboard Address
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\3ckpi0yr2.0.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
1 459
Read events
1 420
Write events
39
Delete events
0

Modification events

(PID) Process:(2804) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2804) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2804) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2804) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(2804) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\【★】CapMonster v2.10.16.0 +SQLiDumper_10.2_Cracked_By_Angeal【★】.rar
(PID) Process:(2804) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2804) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2804) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2804) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3440) SearchProtocolHost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
5
Suspicious files
0
Text files
8
Unknown types
1

Dropped files

PID
Process
Filename
Type
2804WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2804.7813\【★】CapMonster v2.10.16.0 +SQLiDumper_10.2_Cracked_By_Angeal【★】\SQLiDumper_10.2_Cracked_By_Angeal_Cleaned_FullyPatched\ChilkatDotNet46.dll
MD5:
SHA256:
2804WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2804.7813\【★】CapMonster v2.10.16.0 +SQLiDumper_10.2_Cracked_By_Angeal【★】\SQLiDumper_10.2_Cracked_By_Angeal_Cleaned_FullyPatched\LNG\English.xml
MD5:
SHA256:
2804WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2804.7813\【★】CapMonster v2.10.16.0 +SQLiDumper_10.2_Cracked_By_Angeal【★】\SQLiDumper_10.2_Cracked_By_Angeal_Cleaned_FullyPatched\LNG\French.xml
MD5:
SHA256:
2804WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2804.7813\【★】CapMonster v2.10.16.0 +SQLiDumper_10.2_Cracked_By_Angeal【★】\SQLiDumper_10.2_Cracked_By_Angeal_Cleaned_FullyPatched\LNG\German.xml
MD5:
SHA256:
2804WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2804.7813\【★】CapMonster v2.10.16.0 +SQLiDumper_10.2_Cracked_By_Angeal【★】\SQLiDumper_10.2_Cracked_By_Angeal_Cleaned_FullyPatched\LNG\Persian.xml
MD5:
SHA256:
2804WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2804.7813\【★】CapMonster v2.10.16.0 +SQLiDumper_10.2_Cracked_By_Angeal【★】\SQLiDumper_10.2_Cracked_By_Angeal_Cleaned_FullyPatched\LNG\Portuguese.xml
MD5:
SHA256:
2804WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2804.7813\【★】CapMonster v2.10.16.0 +SQLiDumper_10.2_Cracked_By_Angeal【★】\SQLiDumper_10.2_Cracked_By_Angeal_Cleaned_FullyPatched\LNG\Russian.xml
MD5:
SHA256:
2804WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2804.7813\【★】CapMonster v2.10.16.0 +SQLiDumper_10.2_Cracked_By_Angeal【★】\SQLiDumper_10.2_Cracked_By_Angeal_Cleaned_FullyPatched\READ ME!!.txt
MD5:
SHA256:
2804WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2804.7813\【★】CapMonster v2.10.16.0 +SQLiDumper_10.2_Cracked_By_Angeal【★】\SQLiDumper_10.2_Cracked_By_Angeal_Cleaned_FullyPatched\Settings.xml
MD5:
SHA256:
2804WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2804.7813\【★】CapMonster v2.10.16.0 +SQLiDumper_10.2_Cracked_By_Angeal【★】\SQLiDumper_10.2_Cracked_By_Angeal_Cleaned_FullyPatched\SkinSoft.VisualStyler.dll
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
1
Threats
6

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1776
SQLI DUMPER_CRACKED_BY_ANGEAL.EXE
162.88.193.70:80
checkip.dyndns.org
US
malicious

DNS requests

Domain
IP
Reputation
checkip.dyndns.org
  • 162.88.193.70
  • 216.146.43.71
  • 131.186.161.70
  • 131.186.113.70
  • 216.146.43.70
shared

Threats

PID
Process
Class
Message
1056
svchost.exe
Misc activity
ET INFO DYNAMIC_DNS Query to *.dyndns. Domain
1056
svchost.exe
Misc activity
AV INFO Query to checkip.dyndns. Domain
1776
SQLI DUMPER_CRACKED_BY_ANGEAL.EXE
Potential Corporate Privacy Violation
ET POLICY External IP Lookup - checkip.dyndns.org
1776
SQLI DUMPER_CRACKED_BY_ANGEAL.EXE
Potential Corporate Privacy Violation
POLICY [PTsecurity] External IP Check checkip.dyndns.org
1776
SQLI DUMPER_CRACKED_BY_ANGEAL.EXE
Potentially Bad Traffic
ET POLICY DynDNS CheckIp External IP Address Server Response
1 ETPRO signatures available at the full report
Process
Message
SQLi Dumper_Cracked_By_Angeal.exe
C:\Users\admin\AppData\Local\Temp\3CKPI0YR2.0.EXE
SQLi Dumper_Cracked_By_Angeal.exe
C:\Users\admin\AppData\Local\Temp\CHILKATDOTNET46.DLL
SQLi Dumper_Cracked_By_Angeal.exe
C:\Users\admin\AppData\Local\Temp\SKINSOFT.VISUALSTYLER.DLL
SQLi Dumper_Cracked_By_Angeal.exe
C:\Users\admin\AppData\Local\Temp\SQLI DUMPER_CRACKED_BY_ANGEAL.EXE