File name:

Safengine Protector V.2.3.9.0.rar

Full analysis: https://app.any.run/tasks/63ad3dfe-e338-468b-9dfe-5d5e70bf5c98
Verdict: Malicious activity
Analysis date: October 30, 2018, 00:49:01
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

73319E8E565937AFB702CE88453067B3

SHA1:

E8EF802C5B87EF5F9A3156FEB56A81E2CE8EAE44

SHA256:

A84616EF8953CCD7C8F680C66BF667B3A09594B97AC9533EBC514CCC531098B0

SSDEEP:

196608:XGKjt2jzzQNS4vMLMJBSm8vXTyW5hDQHhcjU44mVVcP4XDI4DWzhDWeTOyq:XGT34EMJMBTywWcoIzXDI4Q4gO5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • Shielden.exe (PID: 3956)
      • SearchProtocolHost.exe (PID: 3740)
    • Application was dropped or rewritten from another process

      • GetHWID.exe (PID: 3984)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3448)
    • Connects to unusual port

      • Shielden.exe (PID: 3956)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 891572
UncompressedSize: 5028352
OperatingSystem: Win32
ModifyDate: 2016:03:28 15:59:03
PackingMethod: Normal
ArchivedFileName: Safengine Protector V.2.3.9.0\BinRes\libmysql.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
4
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe shielden.exe searchprotocolhost.exe no specs gethwid.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3448"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Safengine Protector V.2.3.9.0.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3740"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe14_ Global\UsGthrCtrlFltPipeMssGthrPipe14 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\windows\system32\version.dll
c:\users\admin\desktop\safengine protector v.2.3.9.0\binres\sekeygensdk.dll
c:\users\admin\desktop\safengine protector v.2.3.9.0\binres\sekeygen.exe
c:\users\admin\desktop\safengine protector v.2.3.9.0\binres\libmysql.dll
c:\windows\system32\notepad.exe
c:\users\admin\desktop\safengine protector v.2.3.9.0\langs\cht.dll
3956"C:\Users\admin\Desktop\Safengine Protector V.2.3.9.0\Shielden.exe" C:\Users\admin\Desktop\Safengine Protector V.2.3.9.0\Shielden.exe
explorer.exe
User:
admin
Company:
Safengine
Integrity Level:
MEDIUM
Description:
Shielden - Professional Software Protection Tool
Exit code:
0
Version:
2.3.9.0
Modules
Images
c:\users\admin\desktop\safengine protector v.2.3.9.0\shielden.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3984"C:\Users\admin\Desktop\Safengine Protector V.2.3.9.0\GetHWID.exe" C:\Users\admin\Desktop\Safengine Protector V.2.3.9.0\GetHWID.exeexplorer.exe
User:
admin
Company:
Safengine
Integrity Level:
MEDIUM
Description:
Safengine - Professional Software Protection Tool
Exit code:
0
Version:
2.3.9.0
Modules
Images
c:\users\admin\desktop\safengine protector v.2.3.9.0\gethwid.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\iphlpapi.dll
Total events
797
Read events
764
Write events
33
Delete events
0

Modification events

(PID) Process:(3448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3448) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Safengine Protector V.2.3.9.0.rar
(PID) Process:(3448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(3448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\AppData\Local\Temp
Executable files
15
Suspicious files
3
Text files
323
Unknown types
1

Dropped files

PID
Process
Filename
Type
3448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3448.25675\Safengine Protector V.2.3.9.0\BinRes\SEKeygen.exeexecutable
MD5:
SHA256:
3448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3448.25675\Safengine Protector V.2.3.9.0\EULA\EULA_EN.txttext
MD5:2295D33BEF6360057B750156A6132AF9
SHA256:1931032C0673713618AB20EE0A242FA1BA6FD79EAB779861DD2F9595D1137368
3448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3448.25675\Safengine Protector V.2.3.9.0\EULA\EULA_CN.txttext
MD5:91F26AEEA49C90E3853A24D7749D361C
SHA256:29793D5F7CA4B6CF5F44BDF9B012DAC4BD0B597DFAFD8495C2920DFD5FA32210
3448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3448.25675\Safengine Protector V.2.3.9.0\GetHWID.exeexecutable
MD5:
SHA256:
3448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3448.25675\Safengine Protector V.2.3.9.0\BinRes\SEKeygenSDK.dllexecutable
MD5:
SHA256:
3448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3448.25675\Safengine Protector V.2.3.9.0\LicenseDB\createdb.sqltext
MD5:D49019E80DD54FEFB7CACCF700A395EA
SHA256:A44673DD8F669BB72AD251CE403F321694AFC8A55EF3C284FFAD95CF45ECB45E
3448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3448.25675\Safengine Protector V.2.3.9.0\LicenseDB\webfront\rewrite\Rewrite.dllexecutable
MD5:AFE04864CB12E4A50DBF78CC7A0286B3
SHA256:318FC2F6025AAEED7A236E57B4B6FC86AB218C9DD49BF2D0B027DCCCB9A49499
3448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3448.25675\Safengine Protector V.2.3.9.0\LicenseDB\webfront\sekeygen_wrapper\sekeygen_wrapper.exeexecutable
MD5:8190989064759D0C49E6E0CF0D4A5B90
SHA256:A330426AC41AA7B9BFA79D305C3B70055661584533C89182C03C1B0CDB427819
3448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3448.25675\Safengine Protector V.2.3.9.0\LicenseDB\webfront\rewrite\httpd.initext
MD5:C12C52945BB1B97E587D025E06E83E92
SHA256:40DFAC1F48A6B94833724ABA4DFB12CA56BD3EBD1C02562666B62620523CC887
3448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3448.25675\Safengine Protector V.2.3.9.0\LicenseDB\webfront\rewrite\Readme.txttext
MD5:C552E70F43692E300917309A3BA29A4F
SHA256:3B6B7E2EB7F183D6B63986F13C51D319C6A6B563B576399E33D3A2161E85E318
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3956
Shielden.exe
183.60.202.234:10002
auth.safengine.com
CHINANET Guangdong province network
CN
unknown

DNS requests

Domain
IP
Reputation
auth.safengine.com
  • 183.60.202.234
unknown

Threats

No threats detected
No debug info