File name:

Cpanel Checker Account.7z

Full analysis: https://app.any.run/tasks/8c70e4b1-1d15-4b1b-9387-00f0c51d201c
Verdict: Malicious activity
Analysis date: August 05, 2023, 04:36:44
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-7z-compressed
File info: 7-zip archive data, version 0.4
MD5:

7AB4FB9AACEC0466282AFFFC20CBB9F7

SHA1:

474BEBC4FF2D1C2B67238C352AF4B2837AB28C7C

SHA256:

AB5ADDCCF05B95B29109A68636D3F4673F634F8A64C522BDF8A828603BBD0240

SSDEEP:

196608:qMsjytQMe5wydATAO2mAg4O9KVHigCqZ7Jss9PY8a7JNTkk6+:qMsjwQHKy2XXB8VCG2oPw7Jim

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • Cpanel_Checker_Account_By_X_Splinter.exe (PID: 3324)
      • Cpanel_Checker_Account_By_X_Splinter.exe (PID: 3988)
    • Application was dropped or rewritten from another process

      • Cpanel_Checker_Account_By_X_Splinter.exe (PID: 3324)
      • Cpanel_Checker_Account_By_X_Splinter.exe (PID: 3988)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Manual execution by a user

      • Cpanel_Checker_Account_By_X_Splinter.exe (PID: 3324)
      • Cpanel_Checker_Account_By_X_Splinter.exe (PID: 3988)
    • The process checks LSA protection

      • Cpanel_Checker_Account_By_X_Splinter.exe (PID: 3988)
      • Cpanel_Checker_Account_By_X_Splinter.exe (PID: 3324)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2804)
    • Reads the machine GUID from the registry

      • Cpanel_Checker_Account_By_X_Splinter.exe (PID: 3324)
      • Cpanel_Checker_Account_By_X_Splinter.exe (PID: 3988)
    • Checks supported languages

      • Cpanel_Checker_Account_By_X_Splinter.exe (PID: 3324)
      • Cpanel_Checker_Account_By_X_Splinter.exe (PID: 3988)
    • Reads the computer name

      • Cpanel_Checker_Account_By_X_Splinter.exe (PID: 3324)
      • Cpanel_Checker_Account_By_X_Splinter.exe (PID: 3988)
    • Reads Environment values

      • Cpanel_Checker_Account_By_X_Splinter.exe (PID: 3324)
      • Cpanel_Checker_Account_By_X_Splinter.exe (PID: 3988)
    • Reads the Internet Settings

      • explorer.exe (PID: 1404)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.7z | 7-Zip compressed archive (v0.4) (57.1)
.7z | 7-Zip compressed archive (gen) (42.8)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
5
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe searchprotocolhost.exe no specs cpanel_checker_account_by_x_splinter.exe no specs cpanel_checker_account_by_x_splinter.exe no specs explorer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1404C:\Windows\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2804"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Cpanel Checker Account.7z"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3324"C:\Users\admin\Desktop\Cpanel Checker Account\Cpanel_Checker_Account_By_X_Splinter.exe" C:\Users\admin\Desktop\Cpanel Checker Account\Cpanel_Checker_Account_By_X_Splinter.exeexplorer.exe
User:
admin
Company:
X-Splinter
Integrity Level:
MEDIUM
Description:
Cpanel Checker Account By X-Splinter
Exit code:
0
Version:
0.3.0.0
Modules
Images
c:\users\admin\desktop\cpanel checker account\cpanel_checker_account_by_x_splinter.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3964"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" C:\Windows\System32\SearchProtocolHost.exeSearchIndexer.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft Windows Search Protocol Host
Exit code:
0
Version:
7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211)
Modules
Images
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3988"C:\Users\admin\Desktop\Cpanel Checker Account\Cpanel_Checker_Account_By_X_Splinter.exe" C:\Users\admin\Desktop\Cpanel Checker Account\Cpanel_Checker_Account_By_X_Splinter.exeexplorer.exe
User:
admin
Company:
X-Splinter
Integrity Level:
MEDIUM
Description:
Cpanel Checker Account By X-Splinter
Exit code:
0
Version:
0.3.0.0
Modules
Images
c:\users\admin\desktop\cpanel checker account\cpanel_checker_account_by_x_splinter.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
9 534
Read events
9 423
Write events
110
Delete events
1

Modification events

(PID) Process:(1404) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0
Operation:writeName:CheckSetting
Value:
01000000D08C9DDF0115D1118C7A00C04FC297EB01000000F6D6788197A75D498472ACE88906AC8D000000000200000000001066000000010000200000009E878810DB7ADAA62BFF5B2995C9135391587830D7B78763BAF891A8E326C1D2000000000E8000000002000020000000708BCEE11BAED4DDD5A3536C5255C2A3EF209C73E80BF0C5975934919F66066C3000000061005E5889DC4149BCED257BF4BA4C21CB59685E22EC16EF02A95B0CEABEBA93FBB032CCA687E18A4BDEBA6F726F319C40000000F064E3528192B7C6D193DF6C50758DA37C0621234E8F51940EC6686BA8A09CA3B94552BD897D898E633AF8A1B24303E938BA186E293CEDBB46D515585CB43CE0
(PID) Process:(2804) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2804) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2804) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2804) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(2804) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2804) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2804) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2804) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1404) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
Executable files
9
Suspicious files
7
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2804WinRAR.exeC:\Users\admin\Desktop\Cpanel Checker Account\About\Website.lnkbinary
MD5:AE734A4CDA96AF11D9DF1BB94A4D3F19
SHA256:E7AC212A1323BEF253D7896E7113F1450C5E3F729DFA969E259FC694CE91F4AC
2804WinRAR.exeC:\Users\admin\Desktop\Cpanel Checker Account\DNGRTx64.dllexecutable
MD5:A428C3E775ADD87C7915381A88061888
SHA256:DDEB3041FF32DA6D6A98E90941EC18F45B7A8AFB2B738394DE3073D774DFDE4A
2804WinRAR.exeC:\Users\admin\Desktop\Cpanel Checker Account\MetroFramework.Fonts.dllexecutable
MD5:B8C8A532438C4B421081EFB258355469
SHA256:15A605129CAC3663BA1DDB98F5798334FBA5E7954EE36A69727299B4E366C2EB
2804WinRAR.exeC:\Users\admin\Desktop\Cpanel Checker Account\MetroFramework.Design.dllexecutable
MD5:C853E9E8C720249198FF376F42328EF9
SHA256:28089707733C92C7FADE97E7B6FAB4007E7B8BFD6DC7A8526A3EA597F1A30845
2804WinRAR.exeC:\Users\admin\Desktop\Cpanel Checker Account\MetroSuite 2.0.dllexecutable
MD5:0D30A398CEC0FF006B6EA2B52D11E744
SHA256:8604BF2A1FE2E94DC1EA1FBD0CF54E77303493B93994DF48479DC683580AA654
1404explorer.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\290532160612e071.automaticDestinations-msbinary
MD5:0B391B363C0C78D11CDE55A0FF84099C
SHA256:E8939AE738266060FC95FBF1DB509BB81678461861FDBAAF65316D66E9BB57A6
2804WinRAR.exeC:\Users\admin\Desktop\Cpanel Checker Account\xNet.dllexecutable
MD5:AC1DCEDDBC66A1AB7915AC9931F0CFEC
SHA256:CC949931EF9533ADCED83F3D58862E9732E5DB7AD17B5FD4CB9D209A99EDB592
1404explorer.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\Cpanel Checker Account.7z.lnkbinary
MD5:0516215B552D85E7061A35D09A69A4E3
SHA256:5F647D78EEFACD2511C32C8325D031D94B448DD78F9E49D246E634B18F0CE570
2804WinRAR.exeC:\Users\admin\Desktop\Cpanel Checker Account\About\YouTube.lnkbinary
MD5:D30CF9EF86B61E037A8F1F476CA467E8
SHA256:EC04B3FD4461883502B986783A9899B0D937C122A29A081C334A5DAFCB9E1306
2804WinRAR.exeC:\Users\admin\Desktop\Cpanel Checker Account\Cpanel_Checker_Account_By_X_Splinter.exeexecutable
MD5:0B6F5586EA466A908B6CCB62BDD25C37
SHA256:3184CE14467002A94600422F7D5B6ED52567E8A6161A596D1414AD19D6263DA1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown
2640
svchost.exe
239.255.255.250:1900
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info