File name:

1.rar

Full analysis: https://app.any.run/tasks/c7960faa-0c10-45b3-ad0a-067671ffc467
Verdict: Malicious activity
Analysis date: January 22, 2019, 14:37:11
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

B8A12C173AA783BC319D5825B7A0B137

SHA1:

25855266945257271BB5103FC422C22FA89C29B5

SHA256:

B7CFF66589AA4D091942216170769B0FAC6ECA229C4BC256CEF0F10C5AAC9C80

SSDEEP:

196608:EksbLyCUyKLQ2XlbLNPsszqipi/buJnKaxpm3S2WGqXM6GH61iHDyw+9m4PxdaJc:ERXljKNlbLNUszC/beKk0S2WGqPFwUmS

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • Spotify Checker (Saves All Accounts).exe (PID: 3368)
      • Spotify Checker (Saves All Accounts).exe (PID: 2272)
      • Spotify Checker.exe (PID: 3404)
      • Spotify Checker.exe (PID: 2320)
    • Loads dropped or rewritten executable

      • Spotify Checker (Saves All Accounts).exe (PID: 2272)
      • Spotify Checker.exe (PID: 2320)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3204)
      • Spotify Checker (Saves All Accounts).exe (PID: 3368)
      • Spotify Checker.exe (PID: 3404)
    • Loads Python modules

      • Spotify Checker (Saves All Accounts).exe (PID: 2272)
      • Spotify Checker.exe (PID: 2320)
    • Application launched itself

      • Spotify Checker.exe (PID: 3404)
  • INFO

    • Dropped object may contain Bitcoin addresses

      • Spotify Checker (Saves All Accounts).exe (PID: 3368)
      • Spotify Checker.exe (PID: 3404)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
5
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe spotify checker (saves all accounts).exe spotify checker (saves all accounts).exe no specs spotify checker.exe spotify checker.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2272"C:\Users\admin\Desktop\Spotify by Rebels\Spotify Checker (Saves All Accounts).exe" C:\Users\admin\Desktop\Spotify by Rebels\Spotify Checker (Saves All Accounts).exeSpotify Checker (Saves All Accounts).exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225786
Modules
Images
c:\users\admin\desktop\spotify by rebels\spotify checker (saves all accounts).exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\temp\_mei33682\python36.dll
2320"C:\Users\admin\Desktop\Spotify by Rebels\Spotify Checker.exe" C:\Users\admin\Desktop\Spotify by Rebels\Spotify Checker.exeSpotify Checker.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225786
Modules
Images
c:\users\admin\desktop\spotify by rebels\spotify checker.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\temp\_mei34042\python36.dll
3204"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\1.rar"C:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.60.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3368"C:\Users\admin\Desktop\Spotify by Rebels\Spotify Checker (Saves All Accounts).exe" C:\Users\admin\Desktop\Spotify by Rebels\Spotify Checker (Saves All Accounts).exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225786
Modules
Images
c:\users\admin\desktop\spotify by rebels\spotify checker (saves all accounts).exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\apphelp.dll
3404"C:\Users\admin\Desktop\Spotify by Rebels\Spotify Checker.exe" C:\Users\admin\Desktop\Spotify by Rebels\Spotify Checker.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225786
Modules
Images
c:\users\admin\desktop\spotify by rebels\spotify checker.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\apphelp.dll
Total events
419
Read events
411
Write events
8
Delete events
0

Modification events

(PID) Process:(3204) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3204) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3204) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3204) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\1.rar
(PID) Process:(3204) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3204) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3204) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(3204) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
28
Suspicious files
2
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
3204WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3204.36576\Spotify by Rebels\Spotify Checker.exeexecutable
MD5:
SHA256:
3368Spotify Checker (Saves All Accounts).exeC:\Users\admin\AppData\Local\Temp\_MEI33682\Spotify.exe.manifestxml
MD5:
SHA256:
3204WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3204.36576\Spotify by Rebels\Spotify Checker (Saves All Accounts).exeexecutable
MD5:
SHA256:
3368Spotify Checker (Saves All Accounts).exeC:\Users\admin\AppData\Local\Temp\_MEI33682\_ctypes.pydexecutable
MD5:
SHA256:
3368Spotify Checker (Saves All Accounts).exeC:\Users\admin\AppData\Local\Temp\_MEI33682\base_library.zipcompressed
MD5:
SHA256:
3368Spotify Checker (Saves All Accounts).exeC:\Users\admin\AppData\Local\Temp\_MEI33682\_bz2.pydexecutable
MD5:71E21C31F062E87128896B8479AA42E7
SHA256:7AC6B18230C416ED697DD5A7B4B256517582601FF7FB3A2054D6E76CC3E9BA6B
3204WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa3204.36576\Spotify by Rebels\combo.txttext
MD5:ECAA88F7FA0BF610A5A26CF545DCD3AA
SHA256:F1945CD6C19E56B3C1C78943EF5EC18116907A4CA1EFC40A57D48AB1DB7ADFC5
3368Spotify Checker (Saves All Accounts).exeC:\Users\admin\AppData\Local\Temp\_MEI33682\pyexpat.pydexecutable
MD5:2D6F708AA62626B34CAD8E83C4B6AE87
SHA256:FFC8EDB6144E3748831FC77D70F5C9876A2DF2856CC007B6F2512A35F2538642
3368Spotify Checker (Saves All Accounts).exeC:\Users\admin\AppData\Local\Temp\_MEI33682\_ssl.pydexecutable
MD5:0F43F328684423CC7B877D2B26B6AF86
SHA256:71E5C04D7B6FB5C93A3800B617213B38B1FA765350F767E80E4EEFDBEBD48AFD
3368Spotify Checker (Saves All Accounts).exeC:\Users\admin\AppData\Local\Temp\_MEI33682\_hashlib.pydexecutable
MD5:60C61C3644981A26DE376FA0B827CB07
SHA256:F86358BA06A4DD02DCAC7E457724F10F0BA4F4618C8AE22660FA42ECD28AE284
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info