File name:

Anonymous Keylogger.rar

Full analysis: https://app.any.run/tasks/a6b9b05a-1fc2-48c8-a42f-b3bfde20d6d0
Verdict: Malicious activity
Analysis date: March 30, 2021, 00:25:41
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

F07C8799BFD77D6A647AB6AF23F79CB9

SHA1:

1043CFD46B54C27EDF90F755A11214C14AD0C30E

SHA256:

AA167C0857BA85D9AC538EEDABF4C35E26D0E39FD206AF905C1B47C9C0F44701

SSDEEP:

98304:0sB9N1sEvNr95a9VcWieZUmCwAPP61cjkGNYHDt/2s8Du3:0293scS923eZUmCwj1OrNW/2siy

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Windows Services.exe (PID: 1468)
      • Runtime Explorer.exe (PID: 3208)
      • Secure System Shell.exe (PID: 2596)
    • Writes to a start menu file

      • Launcher.exe (PID: 2432)
    • Changes the autorun value in the registry

      • Launcher.exe (PID: 2432)
  • SUSPICIOUS

    • Executes PowerShell scripts

      • Launcher.exe (PID: 2432)
    • Creates files in the user directory

      • powershell.exe (PID: 1748)
      • Launcher.exe (PID: 2432)
    • Creates files in the Windows directory

      • Launcher.exe (PID: 2432)
    • Drops a file with a compile date too recent

      • Launcher.exe (PID: 2432)
    • Executable content was dropped or overwritten

      • Launcher.exe (PID: 2432)
  • INFO

    • Manual execution by user

      • Anonymous Keylogger.exe (PID: 1792)
      • ak.exe (PID: 2520)
    • Dropped object may contain Bitcoin addresses

      • Launcher.exe (PID: 2432)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
53
Monitored processes
9
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start winrar.exe no specs anonymous keylogger.exe no specs launcher.exe powershell.exe no specs ak.exe windows services.exe no specs secure system shell.exe no specs runtime explorer.exe no specs ak.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2248"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Anonymous Keylogger.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1792"C:\Users\admin\Desktop\Anonymous Keylogger\Anonymous Keylogger.exe" C:\Users\admin\Desktop\Anonymous Keylogger\Anonymous Keylogger.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Launcher
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\anonymous keylogger\anonymous keylogger.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2432"C:\Users\admin\Desktop\Anonymous Keylogger\lib\Launcher.exe" C:\Users\admin\Desktop\Anonymous Keylogger\lib\Launcher.exe
Anonymous Keylogger.exe
User:
admin
Integrity Level:
HIGH
Description:
Launcher
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\anonymous keylogger\lib\launcher.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
1748"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" add-mppreference -exclusionpath C:\Windows\IMF\C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeLauncher.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
2936"C:\Users\admin\Desktop\Anonymous Keylogger\lib\ak.exe" C:\Users\admin\Desktop\Anonymous Keylogger\lib\ak.exe
Anonymous Keylogger.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\desktop\anonymous keylogger\lib\ak.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1468"C:\Windows\IMF\Windows Services.exe" {Arguments If Needed}C:\Windows\IMF\Windows Services.exeLauncher.exe
User:
admin
Integrity Level:
HIGH
Description:
Windows Services
Version:
1.0.0.0
Modules
Images
c:\windows\imf\windows services.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
2596"C:\Windows\IMF\Secure System Shell.exe" C:\Windows\IMF\Secure System Shell.exeWindows Services.exe
User:
admin
Integrity Level:
HIGH
Description:
Secure System Shell
Version:
1.0.0.0
Modules
Images
c:\windows\imf\secure system shell.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
3208"C:\Windows\IMF\Runtime Explorer.exe" C:\Windows\IMF\Runtime Explorer.exeWindows Services.exe
User:
admin
Company:
Control Service
Integrity Level:
HIGH
Version:
1.00
Modules
Images
c:\windows\imf\runtime explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2520"C:\Users\admin\Desktop\Anonymous Keylogger\lib\ak.exe" C:\Users\admin\Desktop\Anonymous Keylogger\lib\ak.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\desktop\anonymous keylogger\lib\ak.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
958
Read events
881
Write events
77
Delete events
0

Modification events

(PID) Process:(2248) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2248) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2248) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2248) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\13D\52C64B7E
Operation:writeName:@C:\Windows\system32\NetworkExplorer.dll,-1
Value:
Network
(PID) Process:(2248) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Anonymous Keylogger.rar
(PID) Process:(2248) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2248) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2248) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2248) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1792) Anonymous Keylogger.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
Executable files
3
Suspicious files
4
Text files
0
Unknown types
1

Dropped files

PID
Process
Filename
Type
2248WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2248.29760\Anonymous Keylogger\Anonymous Keylogger.exe
MD5:
SHA256:
2248WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2248.29760\Anonymous Keylogger\Colorful.Console.dll
MD5:
SHA256:
2248WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2248.29760\Anonymous Keylogger\geckodriver.exe
MD5:
SHA256:
2248WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2248.29760\Anonymous Keylogger\lib\ak.exe
MD5:
SHA256:
2248WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2248.29760\Anonymous Keylogger\lib\Ionic.Zip.dll
MD5:
SHA256:
2248WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2248.29760\Anonymous Keylogger\lib\IronPython.SQLite.dll
MD5:
SHA256:
2248WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2248.29760\Anonymous Keylogger\lib\Launcher.exe
MD5:
SHA256:
2248WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2248.29760\Anonymous Keylogger\lib\LICENCE.dat
MD5:
SHA256:
2248WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2248.29760\Anonymous Keylogger\lib\MetroFramework.Design.dll
MD5:
SHA256:
2248WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2248.29760\Anonymous Keylogger\LiteDB.dll
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info