File name:

Safengine Protector V.2.3.9.0.rar

Full analysis: https://app.any.run/tasks/63ad3dfe-e338-468b-9dfe-5d5e70bf5c98
Verdict: Malicious activity
Analysis date: October 30, 2018, 00:49:01
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v4, os: Win32
MD5:

73319E8E565937AFB702CE88453067B3

SHA1:

E8EF802C5B87EF5F9A3156FEB56A81E2CE8EAE44

SHA256:

A84616EF8953CCD7C8F680C66BF667B3A09594B97AC9533EBC514CCC531098B0

SSDEEP:

196608:XGKjt2jzzQNS4vMLMJBSm8vXTyW5hDQHhcjU44mVVcP4XDI4DWzhDWeTOyq:XGT34EMJMBTywWcoIzXDI4Q4gO5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • GetHWID.exe (PID: 3984)
    • Loads dropped or rewritten executable

      • Shielden.exe (PID: 3956)
      • SearchProtocolHost.exe (PID: 3740)
  • SUSPICIOUS

    • Connects to unusual port

      • Shielden.exe (PID: 3956)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3448)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v-4.x) (58.3)
.rar | RAR compressed archive (gen) (41.6)

EXIF

ZIP

CompressedSize: 891572
UncompressedSize: 5028352
OperatingSystem: Win32
ModifyDate: 2016:03:28 15:59:03
PackingMethod: Normal
ArchivedFileName: Safengine Protector V.2.3.9.0\BinRes\libmysql.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
4
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe shielden.exe searchprotocolhost.exe no specs gethwid.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3448"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Safengine Protector V.2.3.9.0.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3740"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe14_ Global\UsGthrCtrlFltPipeMssGthrPipe14 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\windows\system32\version.dll
c:\users\admin\desktop\safengine protector v.2.3.9.0\binres\sekeygensdk.dll
c:\users\admin\desktop\safengine protector v.2.3.9.0\binres\sekeygen.exe
c:\users\admin\desktop\safengine protector v.2.3.9.0\binres\libmysql.dll
c:\windows\system32\notepad.exe
c:\users\admin\desktop\safengine protector v.2.3.9.0\langs\cht.dll
3956"C:\Users\admin\Desktop\Safengine Protector V.2.3.9.0\Shielden.exe" C:\Users\admin\Desktop\Safengine Protector V.2.3.9.0\Shielden.exe
explorer.exe
User:
admin
Company:
Safengine
Integrity Level:
MEDIUM
Description:
Shielden - Professional Software Protection Tool
Exit code:
0
Version:
2.3.9.0
Modules
Images
c:\users\admin\desktop\safengine protector v.2.3.9.0\shielden.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3984"C:\Users\admin\Desktop\Safengine Protector V.2.3.9.0\GetHWID.exe" C:\Users\admin\Desktop\Safengine Protector V.2.3.9.0\GetHWID.exeexplorer.exe
User:
admin
Company:
Safengine
Integrity Level:
MEDIUM
Description:
Safengine - Professional Software Protection Tool
Exit code:
0
Version:
2.3.9.0
Modules
Images
c:\users\admin\desktop\safengine protector v.2.3.9.0\gethwid.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\iphlpapi.dll
Total events
797
Read events
764
Write events
33
Delete events
0

Modification events

(PID) Process:(3448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3448) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Safengine Protector V.2.3.9.0.rar
(PID) Process:(3448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(3448) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\AppData\Local\Temp
Executable files
15
Suspicious files
3
Text files
323
Unknown types
1

Dropped files

PID
Process
Filename
Type
3448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3448.25675\Safengine Protector V.2.3.9.0\BinRes\SEKeygenSDK.dllexecutable
MD5:
SHA256:
3448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3448.25675\Safengine Protector V.2.3.9.0\GetHWID.exeexecutable
MD5:
SHA256:
3448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3448.25675\Safengine Protector V.2.3.9.0\BinRes\SEKeygen.exeexecutable
MD5:
SHA256:
3448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3448.25675\Safengine Protector V.2.3.9.0\dbghelp.dllexecutable
MD5:4003E34416EBD25E4C115D49DC15E1A7
SHA256:C06430B8CB025BE506BE50A756488E1BCC3827C4F45158D93E4E3EEB98CE1E4F
3448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3448.25675\Safengine Protector V.2.3.9.0\EULA\EULA_CN.txttext
MD5:91F26AEEA49C90E3853A24D7749D361C
SHA256:29793D5F7CA4B6CF5F44BDF9B012DAC4BD0B597DFAFD8495C2920DFD5FA32210
3448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3448.25675\Safengine Protector V.2.3.9.0\LicenseDB\webfront\rewrite\httpd.initext
MD5:C12C52945BB1B97E587D025E06E83E92
SHA256:40DFAC1F48A6B94833724ABA4DFB12CA56BD3EBD1C02562666B62620523CC887
3448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3448.25675\Safengine Protector V.2.3.9.0\LicenseDB\webfront\rewrite\mtbnotif.dllexecutable
MD5:E75014EF4096B22FBD120398424102A5
SHA256:9733873F8B5847BD5F9C5BA133798492313D36A352A975659B305E02A13CA798
3448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3448.25675\Safengine Protector V.2.3.9.0\EULA\EULA_EN.txttext
MD5:2295D33BEF6360057B750156A6132AF9
SHA256:1931032C0673713618AB20EE0A242FA1BA6FD79EAB779861DD2F9595D1137368
3448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3448.25675\Safengine Protector V.2.3.9.0\EULA\TaggantLicense.txttext
MD5:90808DA4A6E2E1A1E3B48980FFEFA41E
SHA256:FA672628D6B45C5C4D56D5D00205C5D90C66A40FA801F67BA63523DF326E8051
3448WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3448.25675\Safengine Protector V.2.3.9.0\HelpCN.chmchm
MD5:184444AE248B1C476DF648E408BB0717
SHA256:800180DA47DD2741A9BD37FDE29EC31A4693FCD84863F2F4474119943A244791
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3956
Shielden.exe
183.60.202.234:10002
auth.safengine.com
CHINANET Guangdong province network
CN
unknown

DNS requests

Domain
IP
Reputation
auth.safengine.com
  • 183.60.202.234
unknown

Threats

No threats detected
No debug info