File name:

Desktop.rar

Full analysis: https://app.any.run/tasks/47deec78-c843-48df-bfb0-07cce18cd4ed
Verdict: Malicious activity
Analysis date: June 25, 2023, 18:41:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
nitol
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

547189414E2818270A4F645687603CBF

SHA1:

7DB97C43B0DED660C61330AB6980F925723ACB10

SHA256:

B2782ABE26D2755FDC5AAEBECE3504345D0F73CD9DFFCB8C0A2B37BEF99A6B9E

SSDEEP:

6144:pUucPtyVH+xW3Uw+o0CqMKxkZhK1jMSgXPgY4pKbCv:p/UdxRwhRqp6gY4pwO

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • a.exe (PID: 3552)
      • Cccogae.exe (PID: 3652)
      • aa.exe (PID: 4036)
      • Cccogae.exe (PID: 2516)
      • Wywuaym.exe (PID: 2588)
      • Cccogae.exe (PID: 2508)
      • aaa.exe (PID: 2864)
      • Vjezaqn.exe (PID: 1188)
      • Vjezaqn.exe (PID: 1832)
    • NITOL detected by memory dumps

      • Wywuaym.exe (PID: 2588)
      • a.exe (PID: 3552)
      • aa.exe (PID: 4036)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • a.exe (PID: 3552)
      • aa.exe (PID: 4036)
      • aaa.exe (PID: 2864)
    • Executes as Windows Service

      • Cccogae.exe (PID: 3652)
      • Wywuaym.exe (PID: 2588)
      • Vjezaqn.exe (PID: 1188)
    • Creates or modifies Windows services

      • a.exe (PID: 3552)
      • aa.exe (PID: 4036)
      • Wywuaym.exe (PID: 2588)
      • aaa.exe (PID: 2864)
    • Application launched itself

      • Cccogae.exe (PID: 3652)
      • Cccogae.exe (PID: 2516)
      • Vjezaqn.exe (PID: 1188)
    • Connects to unusual port

      • aa.exe (PID: 4036)
      • a.exe (PID: 3552)
      • Wywuaym.exe (PID: 2588)
      • aaa.exe (PID: 2864)
  • INFO

    • Manual execution by a user

      • WinRAR.exe (PID: 3948)
      • a.exe (PID: 3552)
      • aa.exe (PID: 4036)
      • aaa.exe (PID: 2864)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3948)
    • Checks supported languages

      • a.exe (PID: 3552)
      • Cccogae.exe (PID: 3652)
      • aa.exe (PID: 4036)
      • Cccogae.exe (PID: 2516)
      • Wywuaym.exe (PID: 2588)
      • Cccogae.exe (PID: 2508)
      • aaa.exe (PID: 2864)
      • Vjezaqn.exe (PID: 1188)
      • Vjezaqn.exe (PID: 1832)
    • Creates files in the program directory

      • a.exe (PID: 3552)
      • aa.exe (PID: 4036)
      • aaa.exe (PID: 2864)
    • Reads the computer name

      • a.exe (PID: 3552)
      • Cccogae.exe (PID: 3652)
      • Cccogae.exe (PID: 2516)
      • Wywuaym.exe (PID: 2588)
      • Cccogae.exe (PID: 2508)
      • aa.exe (PID: 4036)
      • Vjezaqn.exe (PID: 1188)
      • Vjezaqn.exe (PID: 1832)
      • aaa.exe (PID: 2864)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
55
Monitored processes
11
Malicious processes
7
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs winrar.exe #NITOL a.exe cccogae.exe no specs #NITOL aa.exe cccogae.exe no specs #NITOL wywuaym.exe cccogae.exe no specs aaa.exe vjezaqn.exe no specs vjezaqn.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1188"C:\Program Files\Microsoft Gaigkc\Vjezaqn.exe"C:\Program Files\Microsoft Gaigkc\Vjezaqn.exeservices.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Exit code:
0
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\microsoft gaigkc\vjezaqn.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
1832"C:\Program Files\Microsoft Gaigkc\Vjezaqn.exe" Win7C:\Program Files\Microsoft Gaigkc\Vjezaqn.exeVjezaqn.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Exit code:
0
Modules
Images
c:\program files\microsoft gaigkc\vjezaqn.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
2508"C:\Program Files\Cccogae.exe" Win7C:\Program Files\Cccogae.exeCccogae.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Exit code:
0
Modules
Images
c:\program files\cccogae.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
2516"C:\Program Files\Cccogae.exe" Win7C:\Program Files\Cccogae.exeCccogae.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Exit code:
0
Modules
Images
c:\program files\cccogae.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msvcrt.dll
2588"C:\Program Files\Wywuaym.exe"C:\Program Files\Wywuaym.exe
services.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Exit code:
0
Modules
Images
c:\program files\wywuaym.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
2864"C:\Users\admin\Desktop\aaa.exe" C:\Users\admin\Desktop\aaa.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\aaa.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
3076"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\Desktop.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
3552"C:\Users\admin\Desktop\a.exe" C:\Users\admin\Desktop\a.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\a.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
3652"C:\Program Files\Cccogae.exe"C:\Program Files\Cccogae.exeservices.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Exit code:
0
Modules
Images
c:\program files\cccogae.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msctf.dll
3948"C:\Program Files\WinRAR\WinRAR.exe" x -iext -ow -ver "-an=C:\Users\admin\Desktop\088b9498e86195680bfc9de8120e8009f1f0423175dd59f6090e3d745006d77f.7z" "-an=C:\Users\admin\Desktop\aa124697017c46741f54e4f827e171d7c3a2cfff4913f1e11c9efb56faf552eb.7z" -- "C:\Users\admin\Desktop\e39309dfcbb2553ed8c93281a6243d89439bc4a46b29773532005316aebdd989.7z" C:\Users\admin\Desktop\C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
Total events
1 564
Read events
1 543
Write events
21
Delete events
0

Modification events

(PID) Process:(3076) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3076) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(3076) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3076) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3076) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3076) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3076) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3076) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3948) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3948) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
Executable files
9
Suspicious files
3
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3076WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3076.46950\088b9498e86195680bfc9de8120e8009f1f0423175dd59f6090e3d745006d77f.7zcompressed
MD5:DDC296CFDD7E35175D724D3A36CD7DB9
SHA256:BF2B7870568F3CFD4D185C6AF0242CF3D14030183CF5ED94EEDE9BA33642639B
3076WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3076.46950\aa124697017c46741f54e4f827e171d7c3a2cfff4913f1e11c9efb56faf552eb.7zcompressed
MD5:CAD6F368AA2DDEE122D8228D0992EE9C
SHA256:BC9A2B4137075EF31FB7D297D6753CC263EC805EE1C1426A24A1621CEEE55750
3076WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3076.46950\e39309dfcbb2553ed8c93281a6243d89439bc4a46b29773532005316aebdd989.7zcompressed
MD5:95123D1D9BDDC63D689EA395AA266529
SHA256:BE59DD9BCEB4F0336BED0E2D8C1B51C081FD5F6DBD29E6D6E03CC52CCEC90CFF
3948WinRAR.exeC:\Users\admin\Desktop\088b9498e86195680bfc9de8120e8009f1f0423175dd59f6090e3d745006d77fexecutable
MD5:BD8611002E01D4F9911E85624D431EB0
SHA256:088B9498E86195680BFC9DE8120E8009F1F0423175DD59F6090E3D745006D77F
3552a.exeC:\Program Files\Cccogae.exeexecutable
MD5:BD8611002E01D4F9911E85624D431EB0
SHA256:088B9498E86195680BFC9DE8120E8009F1F0423175DD59F6090E3D745006D77F
3552a.exeC:\Windows\System32\1191093.bakexecutable
MD5:BD8611002E01D4F9911E85624D431EB0
SHA256:088B9498E86195680BFC9DE8120E8009F1F0423175DD59F6090E3D745006D77F
4036aa.exeC:\Windows\System32\1192328.bakexecutable
MD5:9ADC9644A1956DEE23C63221951DD192
SHA256:AA124697017C46741F54E4F827E171D7C3A2CFFF4913F1E11C9EFB56FAF552EB
3948WinRAR.exeC:\Users\admin\Desktop\aa124697017c46741f54e4f827e171d7c3a2cfff4913f1e11c9efb56faf552ebexecutable
MD5:9ADC9644A1956DEE23C63221951DD192
SHA256:AA124697017C46741F54E4F827E171D7C3A2CFFF4913F1E11C9EFB56FAF552EB
3948WinRAR.exeC:\Users\admin\Desktop\e39309dfcbb2553ed8c93281a6243d89439bc4a46b29773532005316aebdd989executable
MD5:782CBC8660FF9E94E584ADFCBC4CB961
SHA256:E39309DFCBB2553ED8C93281A6243D89439BC4A46B29773532005316AEBDD989
4036aa.exeC:\Program Files\Wywuaym.exeexecutable
MD5:9ADC9644A1956DEE23C63221951DD192
SHA256:AA124697017C46741F54E4F827E171D7C3A2CFFF4913F1E11C9EFB56FAF552EB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
36
DNS requests
16
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1076
svchost.exe
224.0.0.252:5355
unknown
1896
svchost.exe
239.255.255.250:1900
whitelisted
3552
a.exe
103.66.189.149:2220
tuwu.meibu.net
CMB
KR
unknown
4036
aa.exe
103.66.189.149:2220
tuwu.meibu.net
CMB
KR
unknown
2588
Wywuaym.exe
103.66.189.149:2220
tuwu.meibu.net
CMB
KR
unknown
2864
aaa.exe
172.86.127.224:8000
ASN-QUADRANET-GLOBAL
US
unknown

DNS requests

Domain
IP
Reputation
tuwu.meibu.net
  • 103.66.189.149
unknown

Threats

No threats detected
No debug info