File name:

1.rar

Full analysis: https://app.any.run/tasks/c7960faa-0c10-45b3-ad0a-067671ffc467
Verdict: Malicious activity
Analysis date: January 22, 2019, 14:37:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

B8A12C173AA783BC319D5825B7A0B137

SHA1:

25855266945257271BB5103FC422C22FA89C29B5

SHA256:

B7CFF66589AA4D091942216170769B0FAC6ECA229C4BC256CEF0F10C5AAC9C80

SSDEEP:

196608:EksbLyCUyKLQ2XlbLNPsszqipi/buJnKaxpm3S2WGqXM6GH61iHDyw+9m4PxdaJc:ERXljKNlbLNUszC/beKk0S2WGqPFwUmS

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Spotify Checker (Saves All Accounts).exe (PID: 3368)
      • Spotify Checker (Saves All Accounts).exe (PID: 2272)
      • Spotify Checker.exe (PID: 2320)
      • Spotify Checker.exe (PID: 3404)
    • Loads dropped or rewritten executable

      • Spotify Checker (Saves All Accounts).exe (PID: 2272)
      • Spotify Checker.exe (PID: 2320)
  • SUSPICIOUS

    • Loads Python modules

      • Spotify Checker (Saves All Accounts).exe (PID: 2272)
      • Spotify Checker.exe (PID: 2320)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3204)
      • Spotify Checker (Saves All Accounts).exe (PID: 3368)
      • Spotify Checker.exe (PID: 3404)
    • Application launched itself

      • Spotify Checker.exe (PID: 3404)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • Spotify Checker (Saves All Accounts).exe (PID: 3368)
      • Spotify Checker.exe (PID: 3404)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
5
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe spotify checker (saves all accounts).exe spotify checker (saves all accounts).exe no specs spotify checker.exe spotify checker.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2272"C:\Users\admin\Desktop\Spotify by Rebels\Spotify Checker (Saves All Accounts).exe" C:\Users\admin\Desktop\Spotify by Rebels\Spotify Checker (Saves All Accounts).exeSpotify Checker (Saves All Accounts).exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225786
Modules
Images
c:\users\admin\desktop\spotify by rebels\spotify checker (saves all accounts).exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\temp\_mei33682\python36.dll
2320"C:\Users\admin\Desktop\Spotify by Rebels\Spotify Checker.exe" C:\Users\admin\Desktop\Spotify by Rebels\Spotify Checker.exeSpotify Checker.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225786
Modules
Images
c:\users\admin\desktop\spotify by rebels\spotify checker.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\temp\_mei34042\python36.dll
3204"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\1.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3368"C:\Users\admin\Desktop\Spotify by Rebels\Spotify Checker (Saves All Accounts).exe" C:\Users\admin\Desktop\Spotify by Rebels\Spotify Checker (Saves All Accounts).exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225786
Modules
Images
c:\users\admin\desktop\spotify by rebels\spotify checker (saves all accounts).exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\apphelp.dll
3404"C:\Users\admin\Desktop\Spotify by Rebels\Spotify Checker.exe" C:\Users\admin\Desktop\Spotify by Rebels\Spotify Checker.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225786
Modules
Images
c:\users\admin\desktop\spotify by rebels\spotify checker.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\apphelp.dll
Total events
419
Read events
411
Write events
8
Delete events
0

Modification events

(PID) Process:(3204) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3204) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3204) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3204) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\1.rar
(PID) Process:(3204) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3204) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3204) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3204) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
28
Suspicious files
2
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
3204WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3204.36576\Spotify by Rebels\Spotify Checker.exeexecutable
MD5:
SHA256:
3368Spotify Checker (Saves All Accounts).exeC:\Users\admin\AppData\Local\Temp\_MEI33682\_ctypes.pydexecutable
MD5:
SHA256:
3368Spotify Checker (Saves All Accounts).exeC:\Users\admin\AppData\Local\Temp\_MEI33682\base_library.zipcompressed
MD5:
SHA256:
3368Spotify Checker (Saves All Accounts).exeC:\Users\admin\AppData\Local\Temp\_MEI33682\_bz2.pydexecutable
MD5:71E21C31F062E87128896B8479AA42E7
SHA256:7AC6B18230C416ED697DD5A7B4B256517582601FF7FB3A2054D6E76CC3E9BA6B
3368Spotify Checker (Saves All Accounts).exeC:\Users\admin\AppData\Local\Temp\_MEI33682\pyexpat.pydexecutable
MD5:2D6F708AA62626B34CAD8E83C4B6AE87
SHA256:FFC8EDB6144E3748831FC77D70F5C9876A2DF2856CC007B6F2512A35F2538642
3368Spotify Checker (Saves All Accounts).exeC:\Users\admin\AppData\Local\Temp\_MEI33682\_hashlib.pydexecutable
MD5:60C61C3644981A26DE376FA0B827CB07
SHA256:F86358BA06A4DD02DCAC7E457724F10F0BA4F4618C8AE22660FA42ECD28AE284
3368Spotify Checker (Saves All Accounts).exeC:\Users\admin\AppData\Local\Temp\_MEI33682\_ssl.pydexecutable
MD5:0F43F328684423CC7B877D2B26B6AF86
SHA256:71E5C04D7B6FB5C93A3800B617213B38B1FA765350F767E80E4EEFDBEBD48AFD
3368Spotify Checker (Saves All Accounts).exeC:\Users\admin\AppData\Local\Temp\_MEI33682\pywintypes36.dllexecutable
MD5:FF3730F401B5E31012237EFFF446AF13
SHA256:AF06FF85B06D41EC007EBFD3A46D44AD03EBD1FFCF09CB715B966544B9A3B55D
3368Spotify Checker (Saves All Accounts).exeC:\Users\admin\AppData\Local\Temp\_MEI33682\select.pydexecutable
MD5:5497A4FD07A72A0CD5E718556DA11E4F
SHA256:518452A64895022E77C85529DA200779B60B8F644358FC78E8F976853AB263C0
3368Spotify Checker (Saves All Accounts).exeC:\Users\admin\AppData\Local\Temp\_MEI33682\_socket.pydexecutable
MD5:A4237FCA7DCE645BC07BABCD7336426C
SHA256:5B5DA54AA1321F38E4738D4C6E3556E28770A750C61296E69CC35810D65E6675
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info