File name:

goodbyedpi-0.2.3rc3-2.rar

Full analysis: https://app.any.run/tasks/2b438cae-f59d-43d3-ad46-1453eddc1087
Verdict: Malicious activity
Analysis date: April 23, 2025, 10:21:39
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-exec
arch-doc
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

C1B27428A41CBE7EF29A51295B43862D

SHA1:

AEA147368ABFE8D8BD29D2FF7A954C6AADBC79E1

SHA256:

B9911016662D6E1710BBBB5FBF2853310E3C69121542E0157B9A7A2FB66C976B

SSDEEP:

49152:JX50JMT/TE2kx3ukIXKTYLgm30er8GoauaXHclClBluPzsXzVgw1mFIxO7keK+lH:JmJI7M+kGLRZqaLDBEPzsXhgUdO7PkSx

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 976)
  • SUSPICIOUS

    • Drops a system driver (possible attempt to evade defenses)

      • WinRAR.exe (PID: 976)
  • INFO

    • Reads the computer name

      • goodbyedpi.exe (PID: 4188)
    • Checks supported languages

      • goodbyedpi.exe (PID: 4188)
    • Manual execution by a user

      • cmd.exe (PID: 5868)
    • Reads the machine GUID from the registry

      • goodbyedpi.exe (PID: 4188)
    • The sample compiled with english language support

      • WinRAR.exe (PID: 976)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 976)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)

EXIF

ZIP

FileVersion: RAR v5
CompressedSize: 125
UncompressedSize: 130
OperatingSystem: Win32
ArchivedFileName: goodbyedpi-0.2.3rc3-2/0_russia_update_blacklist_file.cmd
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
137
Monitored processes
10
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe sppextcomobj.exe no specs slui.exe no specs rundll32.exe no specs cmd.exe no specs conhost.exe no specs goodbyedpi.exe no specs goodbyedpi.exe no specs goodbyedpi.exe conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
976"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\goodbyedpi-0.2.3rc3-2.rarC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2240"C:\Users\admin\Desktop\goodbyedpi-0.2.3rc3-2\x86_64\goodbyedpi.exe" --set-ttl 5C:\Users\admin\Desktop\goodbyedpi-0.2.3rc3-2\x86_64\goodbyedpi.execmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\goodbyedpi-0.2.3rc3-2\x86_64\goodbyedpi.exe
c:\windows\system32\ntdll.dll
4188"C:\Users\admin\Desktop\goodbyedpi-0.2.3rc3-2\x86_64\goodbyedpi.exe" --set-ttl 5C:\Users\admin\Desktop\goodbyedpi-0.2.3rc3-2\x86_64\goodbyedpi.exe
cmd.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\desktop\goodbyedpi-0.2.3rc3-2\x86_64\goodbyedpi.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4560goodbyedpi.exe --set-ttl 5C:\Users\admin\Desktop\goodbyedpi-0.2.3rc3-2\x86_64\goodbyedpi.execmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\goodbyedpi-0.2.3rc3-2\x86_64\goodbyedpi.exe
c:\windows\system32\ntdll.dll
5048C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
5260\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exegoodbyedpi.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5800"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5868C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\Desktop\goodbyedpi-0.2.3rc3-2\dnsdiscord.cmd" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cmdext.dll
c:\windows\system32\advapi32.dll
6156C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
6228\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
2 161
Read events
2 151
Write events
10
Delete events
0

Modification events

(PID) Process:(976) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(976) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(976) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(976) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\goodbyedpi-0.2.3rc3-2.rar
(PID) Process:(976) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(976) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(976) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(976) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(4188) goodbyedpi.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\System\WinDivert
Operation:writeName:EventMessageFile
Value:
C:\Users\admin\Desktop\goodbyedpi-0.2.3rc3-2\x86_64\WinDivert64.sys
(PID) Process:(4188) goodbyedpi.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\System\WinDivert
Operation:writeName:TypesSupported
Value:
7
Executable files
7
Suspicious files
0
Text files
19
Unknown types
0

Dropped files

PID
Process
Filename
Type
976WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa976.2135\goodbyedpi-0.2.3rc3-2\1_russia_blacklist_YOUTUBE.cmdtext
MD5:55E68F566514148BCF844524B4E99041
SHA256:2712D7700E2F3217E826412A5A773487F08A41451849722FFAA08841B8684496
976WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa976.2135\goodbyedpi-0.2.3rc3-2\dnsdiscord.cmdtext
MD5:8F7D6D47CBA1B2856B4FA40B3AD4224C
SHA256:F1AC8DFCC49E9F75C85F70CADF81B54F8AAD4ED151D612F003F1DFC2DB6128B4
976WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa976.2135\goodbyedpi-0.2.3rc3-2\2_any_country_dnsredir.cmdtext
MD5:77048213EB9358FF71F99667DD08034B
SHA256:E599ADB50F219CFBD620A21167B6CFC68E326DA50836B5985826E45E88D247FE
976WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa976.2135\goodbyedpi-0.2.3rc3-2\licenses\LICENSE-uthash.txttext
MD5:5CC1F1E4C71F19F580458586756C02B4
SHA256:D3C6556E48104C31E3E0C62238C749C2A09CA79EE87DA50B9CD29C6C9027D57D
976WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa976.2135\goodbyedpi-0.2.3rc3-2\russia-youtube.txttext
MD5:91D74100607DBA77EDA0D7A75DACB0CC
SHA256:2D8DE5532BAE45852A3F6D8270E881FC10FEC89F8D9DAEC3D91988A669760F79
976WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa976.2135\goodbyedpi-0.2.3rc3-2\licenses\LICENSE-getline.txttext
MD5:3A7EDEBC3612BCEA2306F73B92342A44
SHA256:EC5F8E03FCCB3842CC62AD79EA5F6F6058988E2721A3E6566E8FB72786D485C4
976WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa976.2135\goodbyedpi-0.2.3rc3-2\service_remove.cmdtext
MD5:204B35D000D6B29C1102B1D8B6A63DC7
SHA256:63915B4B09658CDFEC4C74923650398D9FC497AE3CE9E68C5592337051D2FB64
976WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa976.2135\goodbyedpi-0.2.3rc3-2\russia-blacklist.txttext
MD5:C778017427C08556621C3360E7B60B12
SHA256:227B4961EA7BAFAC9BB5AAF3DFEB2537BEB64169AE37F7658EFEBB573BC9C01A
976WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa976.2135\goodbyedpi-0.2.3rc3-2\2_any_country.cmdtext
MD5:72103C58F2ED536EBC07E19FD00FA2F0
SHA256:17A3D7B8B1E1340F67D3687CE9162199C0A25025941D23954880808403487D07
976WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa976.2135\goodbyedpi-0.2.3rc3-2\service_install_russia_blacklist_dnsredir.cmdtext
MD5:77B1D63472E67C4368961C463CC1D92C
SHA256:450F2B003FB579F897EDED1131C9E893AFDE7B2EBF07B86110449E57ED9A0DA8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
21
DNS requests
14
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
3888
SIHClient.exe
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
3888
SIHClient.exe
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2104
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.16.241.19:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.219.150.101:80
www.microsoft.com
AKAMAI-AS
CL
whitelisted
5496
MoUsoCoreWorker.exe
23.219.150.101:80
www.microsoft.com
AKAMAI-AS
CL
whitelisted
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
4
System
192.168.100.255:137
whitelisted
6544
svchost.exe
20.190.159.128:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
whitelisted
google.com
  • 142.250.184.238
whitelisted
crl.microsoft.com
  • 2.16.241.19
  • 2.16.241.12
whitelisted
www.microsoft.com
  • 23.219.150.101
  • 2.16.253.202
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 20.190.159.128
  • 40.126.31.67
  • 20.190.159.2
  • 20.190.159.71
  • 20.190.159.73
  • 20.190.159.0
  • 20.190.159.75
  • 40.126.31.73
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted
nexusrules.officeapps.live.com
  • 52.111.243.29
whitelisted

Threats

No threats detected
No debug info