File name:

rebels spotify checker.rar

Full analysis: https://app.any.run/tasks/528703f2-c300-4f57-ad69-af2c6c96ff69
Verdict: Malicious activity
Analysis date: December 18, 2018, 18:25:52
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

A77F17D1CC7FA395CBADC9BD904000C9

SHA1:

1E013D9E48DD0D213B17F32F99F9610E9FBF2067

SHA256:

B4BF6A21C2A9F0BD8273E5FA808822B493DBFAFCB27B7F9138B860F0A7E9DA9C

SSDEEP:

98304:cUk5Z80G7zfbLyC8d7xBkKLQvNcXlbLuZ1MpgEs0ZzsfhifxjZk7ze2A/7h+2+TQ:cUkqbLyCUyKLQ2XlbLNPsszqipi/buvR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • Spotify Checker (Saves All Accounts).exe (PID: 3264)
      • Spotify Checker.exe (PID: 2192)
    • Application was dropped or rewritten from another process

      • Spotify Checker (Saves All Accounts).exe (PID: 2388)
      • Spotify Checker.exe (PID: 3340)
      • Spotify Checker (Saves All Accounts).exe (PID: 3264)
      • Spotify Checker.exe (PID: 2192)
  • SUSPICIOUS

    • Loads Python modules

      • Spotify Checker.exe (PID: 2192)
      • Spotify Checker (Saves All Accounts).exe (PID: 3264)
    • Executable content was dropped or overwritten

      • Spotify Checker.exe (PID: 3340)
      • Spotify Checker (Saves All Accounts).exe (PID: 2388)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • Spotify Checker.exe (PID: 3340)
      • Spotify Checker (Saves All Accounts).exe (PID: 2388)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
5
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe no specs spotify checker (saves all accounts).exe spotify checker (saves all accounts).exe no specs spotify checker.exe spotify checker.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2192"C:\Users\admin\Desktop\Spotify Checker.exe" C:\Users\admin\Desktop\Spotify Checker.exeSpotify Checker.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\spotify checker.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\temp\_mei33402\python36.dll
2388"C:\Users\admin\Desktop\Spotify Checker (Saves All Accounts).exe" C:\Users\admin\Desktop\Spotify Checker (Saves All Accounts).exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\spotify checker (saves all accounts).exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\apphelp.dll
3072"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\rebels spotify checker.rar"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3264"C:\Users\admin\Desktop\Spotify Checker (Saves All Accounts).exe" C:\Users\admin\Desktop\Spotify Checker (Saves All Accounts).exeSpotify Checker (Saves All Accounts).exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\spotify checker (saves all accounts).exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\temp\_mei23882\python36.dll
3340"C:\Users\admin\Desktop\Spotify Checker.exe" C:\Users\admin\Desktop\Spotify Checker.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\spotify checker.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\apphelp.dll
Total events
435
Read events
416
Write events
19
Delete events
0

Modification events

(PID) Process:(3072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3072) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\rebels spotify checker.rar
(PID) Process:(3072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(3072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF42000000420000000204000037020000
(PID) Process:(3072) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\General
Operation:writeName:LastFolder
Value:
C:\Users\admin\AppData\Local\Temp
Executable files
26
Suspicious files
2
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
3072WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3072.7983\Spotify Checker (Saves All Accounts).exe
MD5:
SHA256:
3072WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3072.7983\Spotify Checker.exe
MD5:
SHA256:
2388Spotify Checker (Saves All Accounts).exeC:\Users\admin\AppData\Local\Temp\_MEI23882\Spotify.exe.manifestxml
MD5:
SHA256:
2388Spotify Checker (Saves All Accounts).exeC:\Users\admin\AppData\Local\Temp\_MEI23882\_ctypes.pydexecutable
MD5:
SHA256:
2388Spotify Checker (Saves All Accounts).exeC:\Users\admin\AppData\Local\Temp\_MEI23882\base_library.zipcompressed
MD5:
SHA256:
3340Spotify Checker.exeC:\Users\admin\AppData\Local\Temp\_MEI33402\SpotifyChecker.exe.manifestxml
MD5:
SHA256:
2388Spotify Checker (Saves All Accounts).exeC:\Users\admin\AppData\Local\Temp\_MEI23882\_lzma.pydexecutable
MD5:BA76460479EA4A1C29B69810D8890E6C
SHA256:576F184F905EF008ECFD7C7F1CDB4EB1D7D62D1D8BACF53705D7011032EC4B35
2388Spotify Checker (Saves All Accounts).exeC:\Users\admin\AppData\Local\Temp\_MEI23882\_hashlib.pydexecutable
MD5:60C61C3644981A26DE376FA0B827CB07
SHA256:F86358BA06A4DD02DCAC7E457724F10F0BA4F4618C8AE22660FA42ECD28AE284
2388Spotify Checker (Saves All Accounts).exeC:\Users\admin\AppData\Local\Temp\_MEI23882\pyexpat.pydexecutable
MD5:2D6F708AA62626B34CAD8E83C4B6AE87
SHA256:FFC8EDB6144E3748831FC77D70F5C9876A2DF2856CC007B6F2512A35F2538642
2388Spotify Checker (Saves All Accounts).exeC:\Users\admin\AppData\Local\Temp\_MEI23882\select.pydexecutable
MD5:5497A4FD07A72A0CD5E718556DA11E4F
SHA256:518452A64895022E77C85529DA200779B60B8F644358FC78E8F976853AB263C0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info