File name:

Crypto Wallet Cracker v2.3 cracked By @vidhayakji786.zip

Full analysis: https://app.any.run/tasks/449999d7-1288-4d5b-bc32-7d512dca6f75
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: January 15, 2025, 10:30:37
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-exec
stealer
neshta
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

60D98208A4CFCD9DE2AF4186898AC322

SHA1:

5E264C8DF663EB2C430C81C659CB606C5FC93C03

SHA256:

A80C67E2AD0CE7B77D1CD7A9A43560525F6B2AC3D4692F8223D854313A60A336

SSDEEP:

98304:Y755864Dv4pz/PrZgNYDaBh7TKelVrvW2a2gRq/4waqg3KOGaasee8mNEBVN0isA:LU0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 6556)
    • NESHTA mutex has been found

      • Darkminer v6.exe (PID: 5320)
      • Darkminer v6.exe (PID: 5032)
    • Actions looks like stealing of personal data

      • Darkminer v6.exe (PID: 5320)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Darkminer v6.exe (PID: 5320)
      • Darkminer v6.exe (PID: 5032)
    • Reads security settings of Internet Explorer

      • Darkminer v6.exe (PID: 5320)
    • Mutex name with non-standard characters

      • Darkminer v6.exe (PID: 5320)
      • Darkminer v6.exe (PID: 5032)
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6556)
      • WinRAR.exe (PID: 2972)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 6556)
      • WinRAR.exe (PID: 2972)
    • Manual execution by a user

      • mspaint.exe (PID: 5696)
      • Darkminer v6.exe (PID: 5320)
      • WinRAR.exe (PID: 2972)
      • Darkminer v6.exe (PID: 5032)
    • Checks supported languages

      • Darkminer v6.exe (PID: 5320)
      • Darkminer v6.exe (PID: 4764)
      • Darkminer v6.exe (PID: 5032)
    • Reads the computer name

      • Darkminer v6.exe (PID: 5320)
      • Darkminer v6.exe (PID: 4764)
      • Darkminer v6.exe (PID: 5032)
    • Sends debugging messages

      • Darkminer v6.exe (PID: 4764)
      • Darkminer v6.exe (PID: 5256)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2023:10:09 16:58:50
ZipCRC: 0x29015e4d
ZipCompressedSize: 201
ZipUncompressedSize: 428
ZipFileName: Crypto Wallet Cracker v2.3 cracked By @vidhayakji786/Darkminer v6.deps.json
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
134
Monitored processes
8
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe winrar.exe rundll32.exe no specs mspaint.exe no specs #NESHTA darkminer v6.exe darkminer v6.exe #NESHTA darkminer v6.exe darkminer v6.exe

Process information

PID
CMD
Path
Indicators
Parent process
2612C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
2972"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Crypto Wallet Cracker v2.3 cracked By @vidhayakji786.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
4764"C:\Users\admin\AppData\Local\Temp\3582-490\Darkminer v6.exe" C:\Users\admin\AppData\Local\Temp\3582-490\Darkminer v6.exe
Darkminer v6.exe
User:
admin
Company:
Darkminer v6
Integrity Level:
MEDIUM
Description:
Darkminer v6
Exit code:
2147516570
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\3582-490\darkminer v6.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
5032"C:\Users\admin\Desktop\Crypto Wallet Cracker v2.3 cracked By @vidhayakji786\Darkminer v6.exe" C:\Users\admin\Desktop\Crypto Wallet Cracker v2.3 cracked By @vidhayakji786\Darkminer v6.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\crypto wallet cracker v2.3 cracked by @vidhayakji786\darkminer v6.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
5256"C:\Users\admin\AppData\Local\Temp\3582-490\Darkminer v6.exe" C:\Users\admin\AppData\Local\Temp\3582-490\Darkminer v6.exe
Darkminer v6.exe
User:
admin
Company:
Darkminer v6
Integrity Level:
MEDIUM
Description:
Darkminer v6
Exit code:
2147516570
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\3582-490\darkminer v6.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
5320"C:\Users\admin\Desktop\Crypto Wallet Cracker v2.3 cracked By @vidhayakji786\Darkminer v6.exe" C:\Users\admin\Desktop\Crypto Wallet Cracker v2.3 cracked By @vidhayakji786\Darkminer v6.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\desktop\crypto wallet cracker v2.3 cracked by @vidhayakji786\darkminer v6.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
5696"C:\WINDOWS\system32\mspaint.exe" "C:\Users\admin\Desktop\Crypto Wallet Cracker v2.3 cracked By @vidhayakji786\mining_bitcoin_coin_cryptocurrency_money_icon_211007.ico"C:\Windows\System32\mspaint.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Paint
Exit code:
0
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\mspaint.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6556"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Crypto Wallet Cracker v2.3 cracked By @vidhayakji786.zip"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
4 490
Read events
4 411
Write events
65
Delete events
14

Modification events

(PID) Process:(6556) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6556) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6556) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6556) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\Crypto Wallet Cracker v2.3 cracked By @vidhayakji786.zip
(PID) Process:(6556) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6556) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6556) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6556) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(6556) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:15
Value:
(PID) Process:(6556) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\DialogEditHistory\ExtrPath
Operation:delete valueName:14
Value:
Executable files
13
Suspicious files
6
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
6556WinRAR.exeC:\Users\admin\Desktop\Crypto Wallet Cracker v2.3 cracked By @vidhayakji786\Darkminer v6.pdbbinary
MD5:37875F67F67F2F9D750F27AA47DEB6A3
SHA256:A9C743213AD48BFDDCBB332E568F640581AF95B9B522731A1D90F764054E62A0
2972WinRAR.exeC:\Users\admin\Desktop\Crypto Wallet Cracker v2.3 cracked By @vidhayakji786\Darkminer v6.runtimeconfig.jsonbinary
MD5:D720176A229E9D969B40FABEB0BAF62E
SHA256:321B4E463BBACD6113AA337511BDEBF5E7356E9971744346B28424607C7B483A
6556WinRAR.exeC:\Users\admin\Desktop\Crypto Wallet Cracker v2.3 cracked By @vidhayakji786\Darkminer v6.deps.jsonbinary
MD5:F1728A969B6DF0A9DA9D6C94C5015E9A
SHA256:4F0193049D820402B1874E80FD12F131A9D9989812FE548AA7055AE9A406DC30
6556WinRAR.exeC:\Users\admin\Desktop\Crypto Wallet Cracker v2.3 cracked By @vidhayakji786\Darkminer v6.exeexecutable
MD5:82AED2B114642857DA21B46AD83FCF21
SHA256:3603803A35881BF623D136B2288FDC68164C351251C2DA50C295135264A0E2AB
2972WinRAR.exeC:\Users\admin\Desktop\Crypto Wallet Cracker v2.3 cracked By @vidhayakji786\Darkminer v6.pdbbinary
MD5:37875F67F67F2F9D750F27AA47DEB6A3
SHA256:A9C743213AD48BFDDCBB332E568F640581AF95B9B522731A1D90F764054E62A0
2972WinRAR.exeC:\Users\admin\Desktop\Crypto Wallet Cracker v2.3 cracked By @vidhayakji786\Darkminer v6.deps.jsonbinary
MD5:F1728A969B6DF0A9DA9D6C94C5015E9A
SHA256:4F0193049D820402B1874E80FD12F131A9D9989812FE548AA7055AE9A406DC30
2972WinRAR.exeC:\Users\admin\Desktop\Crypto Wallet Cracker v2.3 cracked By @vidhayakji786\Darkminer v6.exeexecutable
MD5:82AED2B114642857DA21B46AD83FCF21
SHA256:3603803A35881BF623D136B2288FDC68164C351251C2DA50C295135264A0E2AB
5320Darkminer v6.exeC:\ProgramData\Adobe\ARM\S\388\AdobeARMHelper.exeexecutable
MD5:85A67D34298E33D2D5A9EC789B6AB594
SHA256:1DEE143B4F88F2375B85C6271A58E2E78FED081BEAE4090678CB2DD7A37FB2D4
2972WinRAR.exeC:\Users\admin\Desktop\Crypto Wallet Cracker v2.3 cracked By @vidhayakji786\mining_bitcoin_coin_cryptocurrency_money_icon_211007.icoimage
MD5:E43373361B937C1035A8D8F9366D8AD0
SHA256:270B31B91C23CAB04604D08DD08EE72EF08F83F8CC8E9450BAA2212B40FE00D1
5320Darkminer v6.exeC:\Users\admin\AppData\Local\Temp\3582-490\Darkminer v6.exeexecutable
MD5:E64ACD0826C046EED8B42583ADB58447
SHA256:B8E4871C8E64009DC97AFF74F987AAFD0466C224A0DB3744631246CABA1D9453
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
33
DNS requests
19
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
640
svchost.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
640
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6524
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6420
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6420
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
640
svchost.exe
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
640
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5064
SearchApp.exe
92.123.104.19:443
www.bing.com
Akamai International B.V.
DE
whitelisted
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 95.101.149.131
whitelisted
google.com
  • 142.250.186.78
whitelisted
www.bing.com
  • 92.123.104.19
  • 92.123.104.37
  • 92.123.104.25
  • 92.123.104.18
  • 92.123.104.21
  • 92.123.104.30
  • 92.123.104.26
  • 92.123.104.33
  • 92.123.104.32
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
login.live.com
  • 20.190.159.75
  • 40.126.31.71
  • 40.126.31.73
  • 40.126.31.69
  • 40.126.31.67
  • 20.190.159.0
  • 20.190.159.68
  • 20.190.159.4
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
arc.msn.com
  • 20.74.47.205
whitelisted
fd.api.iris.microsoft.com
  • 20.74.47.205
whitelisted

Threats

No threats detected
Process
Message
Darkminer v6.exe
The application to execute does not exist: 'C:\Users\admin\AppData\Local\Temp\3582-490\Darkminer v6.dll'.
Darkminer v6.exe
The application to execute does not exist: 'C:\Users\admin\AppData\Local\Temp\3582-490\Darkminer v6.dll'.