File name:

Cpanel Checker Account.7z

Full analysis: https://app.any.run/tasks/8c70e4b1-1d15-4b1b-9387-00f0c51d201c
Verdict: Malicious activity
Analysis date: August 05, 2023, 04:36:44
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

7AB4FB9AACEC0466282AFFFC20CBB9F7

SHA1:

474BEBC4FF2D1C2B67238C352AF4B2837AB28C7C

SHA256:

AB5ADDCCF05B95B29109A68636D3F4673F634F8A64C522BDF8A828603BBD0240

SSDEEP:

196608:qMsjytQMe5wydATAO2mAg4O9KVHigCqZ7Jss9PY8a7JNTkk6+:qMsjwQHKy2XXB8VCG2oPw7Jim

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Cpanel_Checker_Account_By_X_Splinter.exe (PID: 3988)
      • Cpanel_Checker_Account_By_X_Splinter.exe (PID: 3324)
    • Loads dropped or rewritten executable

      • Cpanel_Checker_Account_By_X_Splinter.exe (PID: 3988)
      • Cpanel_Checker_Account_By_X_Splinter.exe (PID: 3324)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2804)
    • Checks supported languages

      • Cpanel_Checker_Account_By_X_Splinter.exe (PID: 3988)
      • Cpanel_Checker_Account_By_X_Splinter.exe (PID: 3324)
    • Reads the computer name

      • Cpanel_Checker_Account_By_X_Splinter.exe (PID: 3988)
      • Cpanel_Checker_Account_By_X_Splinter.exe (PID: 3324)
    • Reads the machine GUID from the registry

      • Cpanel_Checker_Account_By_X_Splinter.exe (PID: 3988)
      • Cpanel_Checker_Account_By_X_Splinter.exe (PID: 3324)
    • The process checks LSA protection

      • Cpanel_Checker_Account_By_X_Splinter.exe (PID: 3988)
      • Cpanel_Checker_Account_By_X_Splinter.exe (PID: 3324)
    • Reads the Internet Settings

      • explorer.exe (PID: 1404)
    • Reads Environment values

      • Cpanel_Checker_Account_By_X_Splinter.exe (PID: 3988)
      • Cpanel_Checker_Account_By_X_Splinter.exe (PID: 3324)
    • Manual execution by a user

      • Cpanel_Checker_Account_By_X_Splinter.exe (PID: 3988)
      • Cpanel_Checker_Account_By_X_Splinter.exe (PID: 3324)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
5
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs cpanel_checker_account_by_x_splinter.exe no specs cpanel_checker_account_by_x_splinter.exe no specs explorer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1404C:\Windows\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2804"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Cpanel Checker Account.7z"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3324"C:\Users\admin\Desktop\Cpanel Checker Account\Cpanel_Checker_Account_By_X_Splinter.exe" C:\Users\admin\Desktop\Cpanel Checker Account\Cpanel_Checker_Account_By_X_Splinter.exeexplorer.exe
User:
admin
Company:
X-Splinter
Integrity Level:
MEDIUM
Description:
Cpanel Checker Account By X-Splinter
Exit code:
0
Version:
0.3.0.0
Modules
Images
c:\users\admin\desktop\cpanel checker account\cpanel_checker_account_by_x_splinter.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3964"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3988"C:\Users\admin\Desktop\Cpanel Checker Account\Cpanel_Checker_Account_By_X_Splinter.exe" C:\Users\admin\Desktop\Cpanel Checker Account\Cpanel_Checker_Account_By_X_Splinter.exeexplorer.exe
User:
admin
Company:
X-Splinter
Integrity Level:
MEDIUM
Description:
Cpanel Checker Account By X-Splinter
Exit code:
0
Version:
0.3.0.0
Modules
Images
c:\users\admin\desktop\cpanel checker account\cpanel_checker_account_by_x_splinter.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
9 534
Read events
9 423
Write events
110
Delete events
1

Modification events

(PID) Process:(1404) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0
Operation:writeName:CheckSetting
Value:
01000000D08C9DDF0115D1118C7A00C04FC297EB01000000F6D6788197A75D498472ACE88906AC8D000000000200000000001066000000010000200000009E878810DB7ADAA62BFF5B2995C9135391587830D7B78763BAF891A8E326C1D2000000000E8000000002000020000000708BCEE11BAED4DDD5A3536C5255C2A3EF209C73E80BF0C5975934919F66066C3000000061005E5889DC4149BCED257BF4BA4C21CB59685E22EC16EF02A95B0CEABEBA93FBB032CCA687E18A4BDEBA6F726F319C40000000F064E3528192B7C6D193DF6C50758DA37C0621234E8F51940EC6686BA8A09CA3B94552BD897D898E633AF8A1B24303E938BA186E293CEDBB46D515585CB43CE0
(PID) Process:(2804) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2804) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2804) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2804) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2804) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2804) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2804) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2804) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1404) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
Executable files
9
Suspicious files
7
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2804WinRAR.exeC:\Users\admin\Desktop\Cpanel Checker Account\About\Facebook.lnkbinary
MD5:F29E7FCD0037E435E5425CE5B90575EC
SHA256:C5ED059E3E164124A6D2F5512AE788EFCC10118D321C5AD8D195102B519DB768
2804WinRAR.exeC:\Users\admin\Desktop\Cpanel Checker Account\About\YouTube.lnkbinary
MD5:D30CF9EF86B61E037A8F1F476CA467E8
SHA256:EC04B3FD4461883502B986783A9899B0D937C122A29A081C334A5DAFCB9E1306
1404explorer.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\Cpanel Checker Account.7z.lnkbinary
MD5:0516215B552D85E7061A35D09A69A4E3
SHA256:5F647D78EEFACD2511C32C8325D031D94B448DD78F9E49D246E634B18F0CE570
2804WinRAR.exeC:\Users\admin\Desktop\Cpanel Checker Account\DNGRTx86.dllexecutable
MD5:A8A0481E38DB76B75C4C61529E479B5F
SHA256:5E97B1088FB36B687C19F1661E43B13B9BEBE233FE2543F66E8B2F8AB07B891B
2804WinRAR.exeC:\Users\admin\Desktop\Cpanel Checker Account\Alert.wavbinary
MD5:9E740AAA2DC47101C4EDBF00DAC7066D
SHA256:AD199B19EA78AE3871C037E1A3D5A8FEB5BF6286A6A300B1E0993BA0BA15220B
2804WinRAR.exeC:\Users\admin\Desktop\Cpanel Checker Account\DNGRTx64.dllexecutable
MD5:A428C3E775ADD87C7915381A88061888
SHA256:DDEB3041FF32DA6D6A98E90941EC18F45B7A8AFB2B738394DE3073D774DFDE4A
2804WinRAR.exeC:\Users\admin\Desktop\Cpanel Checker Account\About\Website.lnkbinary
MD5:AE734A4CDA96AF11D9DF1BB94A4D3F19
SHA256:E7AC212A1323BEF253D7896E7113F1450C5E3F729DFA969E259FC694CE91F4AC
2804WinRAR.exeC:\Users\admin\Desktop\Cpanel Checker Account\Cpanel_Checker_Account_By_X_Splinter.exeexecutable
MD5:0B6F5586EA466A908B6CCB62BDD25C37
SHA256:3184CE14467002A94600422F7D5B6ED52567E8A6161A596D1414AD19D6263DA1
2804WinRAR.exeC:\Users\admin\Desktop\Cpanel Checker Account\MetroFramework.Design.dllexecutable
MD5:C853E9E8C720249198FF376F42328EF9
SHA256:28089707733C92C7FADE97E7B6FAB4007E7B8BFD6DC7A8526A3EA597F1A30845
2804WinRAR.exeC:\Users\admin\Desktop\Cpanel Checker Account\Extreme.Net.dllexecutable
MD5:F79F0E3A0361CAC000E2D3553753CD68
SHA256:8A6518AB7419FBEC3AC9875BAA3AFB410AD1398C7AA622A09CD9084EC6CADFCD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2640
svchost.exe
239.255.255.250:1900
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info