analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

1.rar

Full analysis: https://app.any.run/tasks/c7960faa-0c10-45b3-ad0a-067671ffc467
Verdict: Malicious activity
Analysis date: January 22, 2019, 14:37:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

B8A12C173AA783BC319D5825B7A0B137

SHA1:

25855266945257271BB5103FC422C22FA89C29B5

SHA256:

B7CFF66589AA4D091942216170769B0FAC6ECA229C4BC256CEF0F10C5AAC9C80

SSDEEP:

196608:EksbLyCUyKLQ2XlbLNPsszqipi/buJnKaxpm3S2WGqXM6GH61iHDyw+9m4PxdaJc:ERXljKNlbLNUszC/beKk0S2WGqPFwUmS

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Spotify Checker (Saves All Accounts).exe (PID: 3368)
      • Spotify Checker (Saves All Accounts).exe (PID: 2272)
      • Spotify Checker.exe (PID: 2320)
      • Spotify Checker.exe (PID: 3404)
    • Loads dropped or rewritten executable

      • Spotify Checker (Saves All Accounts).exe (PID: 2272)
      • Spotify Checker.exe (PID: 2320)
  • SUSPICIOUS

    • Application launched itself

      • Spotify Checker.exe (PID: 3404)
    • Executable content was dropped or overwritten

      • Spotify Checker (Saves All Accounts).exe (PID: 3368)
      • Spotify Checker.exe (PID: 3404)
      • WinRAR.exe (PID: 3204)
    • Loads Python modules

      • Spotify Checker.exe (PID: 2320)
      • Spotify Checker (Saves All Accounts).exe (PID: 2272)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • Spotify Checker.exe (PID: 3404)
      • Spotify Checker (Saves All Accounts).exe (PID: 3368)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
5
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe spotify checker (saves all accounts).exe spotify checker (saves all accounts).exe no specs spotify checker.exe spotify checker.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3204"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\1.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.60.0
3368"C:\Users\admin\Desktop\Spotify by Rebels\Spotify Checker (Saves All Accounts).exe" C:\Users\admin\Desktop\Spotify by Rebels\Spotify Checker (Saves All Accounts).exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225786
2272"C:\Users\admin\Desktop\Spotify by Rebels\Spotify Checker (Saves All Accounts).exe" C:\Users\admin\Desktop\Spotify by Rebels\Spotify Checker (Saves All Accounts).exeSpotify Checker (Saves All Accounts).exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225786
3404"C:\Users\admin\Desktop\Spotify by Rebels\Spotify Checker.exe" C:\Users\admin\Desktop\Spotify by Rebels\Spotify Checker.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225786
2320"C:\Users\admin\Desktop\Spotify by Rebels\Spotify Checker.exe" C:\Users\admin\Desktop\Spotify by Rebels\Spotify Checker.exeSpotify Checker.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225786
Total events
419
Read events
411
Write events
0
Delete events
0

Modification events

No data
Executable files
28
Suspicious files
2
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
3368Spotify Checker (Saves All Accounts).exeC:\Users\admin\AppData\Local\Temp\_MEI33682\select.pydexecutable
MD5:5497A4FD07A72A0CD5E718556DA11E4F
SHA256:518452A64895022E77C85529DA200779B60B8F644358FC78E8F976853AB263C0
3368Spotify Checker (Saves All Accounts).exeC:\Users\admin\AppData\Local\Temp\_MEI33682\win32wnet.pydexecutable
MD5:584F28F4CD263FB01E4977315D2A02E3
SHA256:8D5B31B563C1518591AF3D49D1D822D6430438D6F4D8977DC19A81AA105046FA
3368Spotify Checker (Saves All Accounts).exeC:\Users\admin\AppData\Local\Temp\_MEI33682\_lzma.pydexecutable
MD5:BA76460479EA4A1C29B69810D8890E6C
SHA256:576F184F905EF008ECFD7C7F1CDB4EB1D7D62D1D8BACF53705D7011032EC4B35
3368Spotify Checker (Saves All Accounts).exeC:\Users\admin\AppData\Local\Temp\_MEI33682\_bz2.pydexecutable
MD5:71E21C31F062E87128896B8479AA42E7
SHA256:7AC6B18230C416ED697DD5A7B4B256517582601FF7FB3A2054D6E76CC3E9BA6B
3368Spotify Checker (Saves All Accounts).exeC:\Users\admin\AppData\Local\Temp\_MEI33682\unicodedata.pydexecutable
MD5:78027CE0AB903B63DAF977714463F476
SHA256:1DA14014649B632FB660C59D3A08DCE35367AF7AB41201142B0FA21B4B40702B
3368Spotify Checker (Saves All Accounts).exeC:\Users\admin\AppData\Local\Temp\_MEI33682\_ssl.pydexecutable
MD5:0F43F328684423CC7B877D2B26B6AF86
SHA256:71E5C04D7B6FB5C93A3800B617213B38B1FA765350F767E80E4EEFDBEBD48AFD
3368Spotify Checker (Saves All Accounts).exeC:\Users\admin\AppData\Local\Temp\_MEI33682\Spotify.exe.manifestxml
MD5:807929912C367437FCF548E70D9BE752
SHA256:5326428984F1163352AD9F10E3EC823BF62786DABF75979917AFCC17A8851916
3368Spotify Checker (Saves All Accounts).exeC:\Users\admin\AppData\Local\Temp\_MEI33682\base_library.zipcompressed
MD5:19501F3FCC2CF74F110BFA2F1069E51D
SHA256:151F913B4D00C911AC512B2F970AF298A8416F0DA6F8332A8A08B888BAAC2A2C
3368Spotify Checker (Saves All Accounts).exeC:\Users\admin\AppData\Local\Temp\_MEI33682\_hashlib.pydexecutable
MD5:60C61C3644981A26DE376FA0B827CB07
SHA256:F86358BA06A4DD02DCAC7E457724F10F0BA4F4618C8AE22660FA42ECD28AE284
3204WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3204.36576\Spotify by Rebels\Spotify Checker (Saves All Accounts).exeexecutable
MD5:626452DF473FBD01E5E789E9C1FDFBDF
SHA256:D1927820782E6A22C3FE5C6A04F56BA3C0C0333A7EC286901F46321DCC377506
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info