File name:

All Onlyfans Photoes (500+) FREE AND HOT!!!! exclusive forums edition.rar.exe

Full analysis: https://app.any.run/tasks/478098c2-dca9-47b0-afa8-bf6cc0607b49
Verdict: Malicious activity
Threats:

DarkComet RAT is a malicious program designed to remotely control or administer a victim's computer, steal private data and spy on the victim.

Analysis date: October 25, 2022, 18:51:30
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
rat
darkcomet
Indicators:
MIME: application/x-dosexec
File info: MS-DOS executable PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, MZ for MS-DOS
MD5:

1E309019B75BCEDA9141D6D0DE4F506B

SHA1:

30297921257F0A37BA08C4841CB15A4FC55DDE46

SHA256:

B55CDDB6C413CFB06614C11062F955248E552C1033EAF4EDB299BB8286345244

SSDEEP:

12288:up/1Fxn+G8S+aLVj3D+mdgybxB17j7r77DeXgw777777777y777777Yc777g7:uXJhVjT+O

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the login/logoff helper path in the registry

      • All Onlyfans Photoes (500+) FREE AND HOT!!!! exclusive forums edition.rar.exe (PID: 3748)
    • Drops the executable file immediately after the start

      • All Onlyfans Photoes (500+) FREE AND HOT!!!! exclusive forums edition.rar.exe (PID: 3748)
    • Changes the autorun value in the registry

      • All Onlyfans Photoes (500+) FREE AND HOT!!!! exclusive forums edition.rar.exe (PID: 3748)
    • DARKCOMET detected by memory dumps

      • All Onlyfans Photoes (500+) FREE AND HOT!!!! exclusive forums edition.rar.exe (PID: 3172)
    • DARKCOMET was detected

      • All Onlyfans Photoes (500+) FREE AND HOT!!!! exclusive forums edition.rar.exe (PID: 3172)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • All Onlyfans Photoes (500+) FREE AND HOT!!!! exclusive forums edition.rar.exe (PID: 3748)
    • Reads the date of Windows installation

      • All Onlyfans Photoes (500+) FREE AND HOT!!!! exclusive forums edition.rar.exe (PID: 3748)
  • INFO

    • Checks supported languages

      • All Onlyfans Photoes (500+) FREE AND HOT!!!! exclusive forums edition.rar.exe (PID: 3748)
      • All Onlyfans Photoes (500+) FREE AND HOT!!!! exclusive forums edition.rar.exe (PID: 3172)
    • Reads the computer name

      • All Onlyfans Photoes (500+) FREE AND HOT!!!! exclusive forums edition.rar.exe (PID: 3748)
      • All Onlyfans Photoes (500+) FREE AND HOT!!!! exclusive forums edition.rar.exe (PID: 3172)
    • Process checks LSA protection

      • All Onlyfans Photoes (500+) FREE AND HOT!!!! exclusive forums edition.rar.exe (PID: 3748)
      • All Onlyfans Photoes (500+) FREE AND HOT!!!! exclusive forums edition.rar.exe (PID: 3172)
    • Reads default file associations for system extensions

      • All Onlyfans Photoes (500+) FREE AND HOT!!!! exclusive forums edition.rar.exe (PID: 3748)
    • Reads the machine GUID from the registry

      • All Onlyfans Photoes (500+) FREE AND HOT!!!! exclusive forums edition.rar.exe (PID: 3748)
    • Manual execution by user

      • All Onlyfans Photoes (500+) FREE AND HOT!!!! exclusive forums edition.rar.exe (PID: 3172)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

DarkComet

(PID) Process(3172) All Onlyfans Photoes (500+) FREE AND HOT!!!! exclusive forums edition.rar.exe
C2 (1)mstelemetry.ignorelist.com:35695
Version#KCMDDC51#
MutexDC_MUTEX-U2FJMWF
sidGuest16
FWB0
gencodedF730LtyA57o
InstallTrue
COMBOPATH7
Install pathMSDCSC\svchostexe
Registry keyMicroUpdate
Edit date2007-04-16
PersistanceFalse
MELT0
Change Date0
Directory attributesTrue
File attrubutesTrue
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 2012-Jun-07 15:59:53
Detected languages:
  • English - United States
  • French - France
Comments: Remote Service Application
CompanyName: Microsoft Corp.
FileDescription: Remote Service Application
FileVersion: 1, 0, 0, 1
InternalName: MSRSAAPP
LegalCopyright: Copyright (C) 1999
OriginalFilename: MSRSAAP.EXE
ProductName: Remote Service Application
ProductVersion: 4, 0, 0, 0

DOS Header

e_magic: MZ
e_cblp: 64
e_cp: 1
e_crlc: -
e_cparhdr: 2
e_minalloc: -
e_maxalloc: 65535
e_ss: -
e_sp: 184
e_csum: -
e_ip: -
e_cs: -
e_ovno: -
e_oemid: 46080
e_oeminfo: 52489
e_lfanew: 64

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
NumberofSections: 3
TimeDateStamp: 2012-Jun-07 15:59:53
PointerToSymbolTable: -
NumberOfSymbols: -
SizeOfOptionalHeader: 224
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_BYTES_REVERSED_HI
  • IMAGE_FILE_BYTES_REVERSED_LO
  • IMAGE_FILE_DEBUG_STRIPPED
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.MPRESS1
4096
888832
232448
IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
7.99924
.MPRESS2
892928
4584
4608
IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
5.635
.rsrc
901120
168916
168960
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
6.85296

Resources

Title
Entropy
Size
Codepage
Language
Type
1
0
308
Latin 1 / Western European
English - United States
RT_CURSOR
2
0
308
Latin 1 / Western European
English - United States
RT_CURSOR
3
0
308
Latin 1 / Western European
English - United States
RT_CURSOR
4
0
308
Latin 1 / Western European
English - United States
RT_CURSOR
5
0
308
Latin 1 / Western European
English - United States
RT_CURSOR
6
0
308
Latin 1 / Western European
English - United States
RT_CURSOR
7
0
308
Latin 1 / Western European
English - United States
RT_CURSOR
50
7.98755
66261
Latin 1 / Western European
English - United States
RT_ICON
51
5.66833
67624
Latin 1 / Western European
English - United States
RT_ICON
52
5.77954
16936
Latin 1 / Western European
English - United States
RT_ICON

Imports

AVICAP32.DLL
KERNEL32.DLL
SHFolder.dll
URLMON.DLL
WS2_32.DLL
advapi32.dll
comctl32.dll
gdi32.dll
gdiplus.dll
msacm32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start all onlyfans photoes (500+) free and hot!!!! exclusive forums edition.rar.exe #DARKCOMET all onlyfans photoes (500+) free and hot!!!! exclusive forums edition.rar.exe

Process information

PID
CMD
Path
Indicators
Parent process
3172"C:\Users\admin\Desktop\All Onlyfans Photoes (500+) FREE AND HOT!!!! exclusive forums edition.rar.exe" C:\Users\admin\Desktop\All Onlyfans Photoes (500+) FREE AND HOT!!!! exclusive forums edition.rar.exe
Explorer.EXE
User:
admin
Company:
Microsoft Corp.
Integrity Level:
HIGH
Description:
Remote Service Application
Exit code:
0
Version:
1, 0, 0, 1
Modules
Images
c:\users\admin\desktop\all onlyfans photoes (500+) free and hot!!!! exclusive forums edition.rar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
DarkComet
(PID) Process(3172) All Onlyfans Photoes (500+) FREE AND HOT!!!! exclusive forums edition.rar.exe
C2 (1)mstelemetry.ignorelist.com:35695
Version#KCMDDC51#
MutexDC_MUTEX-U2FJMWF
sidGuest16
FWB0
gencodedF730LtyA57o
InstallTrue
COMBOPATH7
Install pathMSDCSC\svchostexe
Registry keyMicroUpdate
Edit date2007-04-16
PersistanceFalse
MELT0
Change Date0
Directory attributesTrue
File attrubutesTrue
3748"C:\Users\admin\Desktop\All Onlyfans Photoes (500+) FREE AND HOT!!!! exclusive forums edition.rar.exe" C:\Users\admin\Desktop\All Onlyfans Photoes (500+) FREE AND HOT!!!! exclusive forums edition.rar.exe
Explorer.EXE
User:
admin
Company:
Microsoft Corp.
Integrity Level:
MEDIUM
Description:
Remote Service Application
Exit code:
0
Version:
1, 0, 0, 1
Modules
Images
c:\users\admin\desktop\all onlyfans photoes (500+) free and hot!!!! exclusive forums edition.rar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
Total events
1 189
Read events
1 186
Write events
3
Delete events
0

Modification events

(PID) Process:(3748) All Onlyfans Photoes (500+) FREE AND HOT!!!! exclusive forums edition.rar.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:MicroUpdate
Value:
C:\Users\admin\Documents\MSDCSC\svchostexe
(PID) Process:(3748) All Onlyfans Photoes (500+) FREE AND HOT!!!! exclusive forums edition.rar.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Operation:writeName:UserInit
Value:
C:\Windows\system32\userinit.exe,C:\Users\admin\Documents\MSDCSC\svchostexe
(PID) Process:(3748) All Onlyfans Photoes (500+) FREE AND HOT!!!! exclusive forums edition.rar.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
1
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3748All Onlyfans Photoes (500+) FREE AND HOT!!!! exclusive forums edition.rar.exeC:\Users\admin\Documents\MSDCSC\svchostexeexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
2
Threats
34

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3172
All Onlyfans Photoes (500+) FREE AND HOT!!!! exclusive forums edition.rar.exe
147.185.221.212:35695
mstelemetry.ignorelist.com
PLAYIT-GG
US
malicious

DNS requests

Domain
IP
Reputation
mstelemetry.ignorelist.com
  • 147.185.221.212
malicious
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

Found threats are available for the paid subscriptions
34 ETPRO signatures available at the full report
No debug info