| File name: | Cpanel Checker Account.7z |
| Full analysis: | https://app.any.run/tasks/8c70e4b1-1d15-4b1b-9387-00f0c51d201c |
| Verdict: | Malicious activity |
| Analysis date: | August 05, 2023, 04:36:44 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-7z-compressed |
| File info: | 7-zip archive data, version 0.4 |
| MD5: | 7AB4FB9AACEC0466282AFFFC20CBB9F7 |
| SHA1: | 474BEBC4FF2D1C2B67238C352AF4B2837AB28C7C |
| SHA256: | AB5ADDCCF05B95B29109A68636D3F4673F634F8A64C522BDF8A828603BBD0240 |
| SSDEEP: | 196608:qMsjytQMe5wydATAO2mAg4O9KVHigCqZ7Jss9PY8a7JNTkk6+:qMsjwQHKy2XXB8VCG2oPw7Jim |
| .7z | | | 7-Zip compressed archive (v0.4) (57.1) |
|---|---|---|
| .7z | | | 7-Zip compressed archive (gen) (42.8) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1404 | C:\Windows\Explorer.EXE | C:\Windows\explorer.exe | — | — | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2804 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Cpanel Checker Account.7z" | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 3324 | "C:\Users\admin\Desktop\Cpanel Checker Account\Cpanel_Checker_Account_By_X_Splinter.exe" | C:\Users\admin\Desktop\Cpanel Checker Account\Cpanel_Checker_Account_By_X_Splinter.exe | — | explorer.exe | |||||||||||
User: admin Company: X-Splinter Integrity Level: MEDIUM Description: Cpanel Checker Account By X-Splinter Exit code: 0 Version: 0.3.0.0 Modules
| |||||||||||||||
| 3964 | "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" | C:\Windows\System32\SearchProtocolHost.exe | — | SearchIndexer.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Windows Search Protocol Host Exit code: 0 Version: 7.00.7601.24542 (win7sp1_ldr_escrow.191209-2211) Modules
| |||||||||||||||
| 3988 | "C:\Users\admin\Desktop\Cpanel Checker Account\Cpanel_Checker_Account_By_X_Splinter.exe" | C:\Users\admin\Desktop\Cpanel Checker Account\Cpanel_Checker_Account_By_X_Splinter.exe | — | explorer.exe | |||||||||||
User: admin Company: X-Splinter Integrity Level: MEDIUM Description: Cpanel Checker Account By X-Splinter Exit code: 0 Version: 0.3.0.0 Modules
| |||||||||||||||
| (PID) Process: | (1404) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0 |
| Operation: | write | Name: | CheckSetting |
Value: 01000000D08C9DDF0115D1118C7A00C04FC297EB01000000F6D6788197A75D498472ACE88906AC8D000000000200000000001066000000010000200000009E878810DB7ADAA62BFF5B2995C9135391587830D7B78763BAF891A8E326C1D2000000000E8000000002000020000000708BCEE11BAED4DDD5A3536C5255C2A3EF209C73E80BF0C5975934919F66066C3000000061005E5889DC4149BCED257BF4BA4C21CB59685E22EC16EF02A95B0CEABEBA93FBB032CCA687E18A4BDEBA6F726F319C40000000F064E3528192B7C6D193DF6C50758DA37C0621234E8F51940EC6686BA8A09CA3B94552BD897D898E633AF8A1B24303E938BA186E293CEDBB46D515585CB43CE0 | |||
| (PID) Process: | (2804) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2804) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip | |||
| (PID) Process: | (2804) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (2804) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (2804) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (2804) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (2804) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
| (PID) Process: | (2804) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | mtime |
Value: 100 | |||
| (PID) Process: | (1404) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2804 | WinRAR.exe | C:\Users\admin\Desktop\Cpanel Checker Account\About\Facebook.lnk | binary | |
MD5:F29E7FCD0037E435E5425CE5B90575EC | SHA256:C5ED059E3E164124A6D2F5512AE788EFCC10118D321C5AD8D195102B519DB768 | |||
| 2804 | WinRAR.exe | C:\Users\admin\Desktop\Cpanel Checker Account\About\YouTube.lnk | binary | |
MD5:D30CF9EF86B61E037A8F1F476CA467E8 | SHA256:EC04B3FD4461883502B986783A9899B0D937C122A29A081C334A5DAFCB9E1306 | |||
| 1404 | explorer.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\Cpanel Checker Account.7z.lnk | binary | |
MD5:0516215B552D85E7061A35D09A69A4E3 | SHA256:5F647D78EEFACD2511C32C8325D031D94B448DD78F9E49D246E634B18F0CE570 | |||
| 2804 | WinRAR.exe | C:\Users\admin\Desktop\Cpanel Checker Account\DNGRTx86.dll | executable | |
MD5:A8A0481E38DB76B75C4C61529E479B5F | SHA256:5E97B1088FB36B687C19F1661E43B13B9BEBE233FE2543F66E8B2F8AB07B891B | |||
| 2804 | WinRAR.exe | C:\Users\admin\Desktop\Cpanel Checker Account\Alert.wav | binary | |
MD5:9E740AAA2DC47101C4EDBF00DAC7066D | SHA256:AD199B19EA78AE3871C037E1A3D5A8FEB5BF6286A6A300B1E0993BA0BA15220B | |||
| 2804 | WinRAR.exe | C:\Users\admin\Desktop\Cpanel Checker Account\DNGRTx64.dll | executable | |
MD5:A428C3E775ADD87C7915381A88061888 | SHA256:DDEB3041FF32DA6D6A98E90941EC18F45B7A8AFB2B738394DE3073D774DFDE4A | |||
| 2804 | WinRAR.exe | C:\Users\admin\Desktop\Cpanel Checker Account\About\Website.lnk | binary | |
MD5:AE734A4CDA96AF11D9DF1BB94A4D3F19 | SHA256:E7AC212A1323BEF253D7896E7113F1450C5E3F729DFA969E259FC694CE91F4AC | |||
| 2804 | WinRAR.exe | C:\Users\admin\Desktop\Cpanel Checker Account\Cpanel_Checker_Account_By_X_Splinter.exe | executable | |
MD5:0B6F5586EA466A908B6CCB62BDD25C37 | SHA256:3184CE14467002A94600422F7D5B6ED52567E8A6161A596D1414AD19D6263DA1 | |||
| 2804 | WinRAR.exe | C:\Users\admin\Desktop\Cpanel Checker Account\MetroFramework.Design.dll | executable | |
MD5:C853E9E8C720249198FF376F42328EF9 | SHA256:28089707733C92C7FADE97E7B6FAB4007E7B8BFD6DC7A8526A3EA597F1A30845 | |||
| 2804 | WinRAR.exe | C:\Users\admin\Desktop\Cpanel Checker Account\Extreme.Net.dll | executable | |
MD5:F79F0E3A0361CAC000E2D3553753CD68 | SHA256:8A6518AB7419FBEC3AC9875BAA3AFB410AD1398C7AA622A09CD9084EC6CADFCD | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2640 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |