download:

/R3nzTheCodeGOD/R3nzSkin/releases/download/v3.3.0/R3nzSkin.zip

Full analysis: https://app.any.run/tasks/3b7c2200-a163-4d23-bb85-b9161268d034
Verdict: Malicious activity
Analysis date: July 24, 2024, 20:49:06
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

F3E11BAFD4A2474FCACA52DF1B79BC5C

SHA1:

CA3FCD4A1F73EA71B601C269474FB39269931970

SHA256:

BA7EC562A7D6B72E2E2E5C48C65A6665FADE6BDBDBE73CB0010C33AF7BED65CC

SSDEEP:

24576:dDvO43PmY5/EzcOmnKssNUovsAEsNK5ceYKJ3/5KgPRQIy:dDvO4/mY5/EzcOmnKssNUovsAESK5ceS

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 6696)
      • R3nzSkin_Injector.exe (PID: 1652)
      • CZ3sC4gz.exe (PID: 2924)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • R3nzSkin_Injector.exe (PID: 1652)
      • CZ3sC4gz.exe (PID: 2924)
  • INFO

    • Manual execution by a user

      • R3nzSkin_Injector.exe (PID: 4324)
      • R3nzSkin_Injector.exe (PID: 1652)
      • CZ3sC4gz.exe (PID: 1956)
      • CZ3sC4gz.exe (PID: 2924)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 6696)
    • Checks supported languages

      • R3nzSkin_Injector.exe (PID: 1652)
      • CZ3sC4gz.exe (PID: 2924)
    • Reads the machine GUID from the registry

      • R3nzSkin_Injector.exe (PID: 1652)
      • CZ3sC4gz.exe (PID: 2924)
    • Reads Environment values

      • R3nzSkin_Injector.exe (PID: 1652)
      • CZ3sC4gz.exe (PID: 2924)
    • Reads the computer name

      • R3nzSkin_Injector.exe (PID: 1652)
      • CZ3sC4gz.exe (PID: 2924)
    • Disables trace logs

      • R3nzSkin_Injector.exe (PID: 1652)
      • CZ3sC4gz.exe (PID: 2924)
    • Checks proxy server information

      • R3nzSkin_Injector.exe (PID: 1652)
      • CZ3sC4gz.exe (PID: 2924)
    • Reads the software policy settings

      • R3nzSkin_Injector.exe (PID: 1652)
      • CZ3sC4gz.exe (PID: 2924)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2024:04:03 14:36:12
ZipCRC: 0x912b6215
ZipCompressedSize: 393950
ZipUncompressedSize: 752640
ZipFileName: R3nzSkin.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
141
Monitored processes
6
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe r3nzskin_injector.exe no specs r3nzskin_injector.exe slui.exe no specs cz3sc4gz.exe no specs cz3sc4gz.exe

Process information

PID
CMD
Path
Indicators
Parent process
1652"C:\Users\admin\Desktop\R3nzSkin_Injector.exe" C:\Users\admin\Desktop\R3nzSkin_Injector.exe
explorer.exe
User:
admin
Company:
R3nzSoftware Inc.
Integrity Level:
HIGH
Description:
R3nSkin DLL Injector
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\r3nzskin_injector.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\msvcrt.dll
1956"C:\Users\admin\Desktop\CZ3sC4gz.exe" C:\Users\admin\Desktop\CZ3sC4gz.exeexplorer.exe
User:
admin
Company:
R3nzSoftware Inc.
Integrity Level:
MEDIUM
Description:
R3nSkin DLL Injector
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\cz3sc4gz.exe
c:\windows\system32\ntdll.dll
2508C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2924"C:\Users\admin\Desktop\CZ3sC4gz.exe" C:\Users\admin\Desktop\CZ3sC4gz.exe
explorer.exe
User:
admin
Company:
R3nzSoftware Inc.
Integrity Level:
HIGH
Description:
R3nSkin DLL Injector
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\cz3sc4gz.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\vcruntime140.dll
4324"C:\Users\admin\Desktop\R3nzSkin_Injector.exe" C:\Users\admin\Desktop\R3nzSkin_Injector.exeexplorer.exe
User:
admin
Company:
R3nzSoftware Inc.
Integrity Level:
MEDIUM
Description:
R3nSkin DLL Injector
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\r3nzskin_injector.exe
c:\windows\system32\ntdll.dll
6696"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Downloads\R3nzSkin.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
5 589
Read events
5 553
Write events
36
Delete events
0

Modification events

(PID) Process:(6696) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(6696) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(6696) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(6696) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Downloads\R3nzSkin.zip
(PID) Process:(6696) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6696) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6696) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6696) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(1652) R3nzSkin_Injector.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\R3nzSkin_Injector_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(1652) R3nzSkin_Injector.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\R3nzSkin_Injector_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
Executable files
4
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
6696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6696.46736\R3nzSkin.dllexecutable
MD5:58DD2BCC4E80B3A3505C21FF541E3924
SHA256:5E5BE7D8AA3A96BFB2A534897B2502799448886F402BC3378D5305A36349B1E1
1652R3nzSkin_Injector.exeC:\Users\admin\Desktop\CZ3sC4gz.exeexecutable
MD5:8AF17734385F55DC58F1CA38BCE22312
SHA256:EA034D7B08A538F827293C3B0742D4C178708AFDFD0F45D47CAD99967B311A97
2924CZ3sC4gz.exeC:\Users\admin\Desktop\TBnr7dQ2.exeexecutable
MD5:8AF17734385F55DC58F1CA38BCE22312
SHA256:EA034D7B08A538F827293C3B0742D4C178708AFDFD0F45D47CAD99967B311A97
6696WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa6696.46736\R3nzSkin_Injector.exeexecutable
MD5:8AF17734385F55DC58F1CA38BCE22312
SHA256:EA034D7B08A538F827293C3B0742D4C178708AFDFD0F45D47CAD99967B311A97
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
44
DNS requests
19
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5272
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
920
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
1756
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6012
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
3488
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4564
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.23.209.189:443
www.bing.com
Akamai International B.V.
GB
unknown
4204
svchost.exe
4.209.32.198:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
3952
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
1652
R3nzSkin_Injector.exe
140.82.121.6:443
api.github.com
GITHUB
US
unknown
1992
slui.exe
40.91.76.224:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
whitelisted
google.com
  • 142.250.186.78
whitelisted
api.github.com
  • 140.82.121.6
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted
www.bing.com
  • 2.23.209.189
  • 2.23.209.187
  • 2.23.209.130
  • 2.23.209.133
  • 2.23.209.140
  • 2.23.209.179
  • 2.23.209.149
  • 2.23.209.182
whitelisted
login.live.com
  • 40.126.31.69
  • 20.190.159.71
  • 20.190.159.64
  • 20.190.159.68
  • 20.190.159.23
  • 40.126.31.73
  • 20.190.159.73
  • 20.190.159.4
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
slscr.update.microsoft.com
  • 40.68.123.157
whitelisted

Threats

No threats detected
No debug info