File name:

Share_bot_10x_faster.rar

Full analysis: https://app.any.run/tasks/451d0861-6728-40ac-a945-89cf111948ac
Verdict: Malicious activity
Analysis date: April 24, 2022, 20:37:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

6D6098165CEC5035A1C768D1B26ED097

SHA1:

9BC6403374C9A4DFF6E1EF4EB5372D639AAC70A9

SHA256:

BCABC73EA6550A27E95E7C43C574BEC88CD7AAA0C74550A730D39AE373B4005C

SSDEEP:

98304:/qfLZ8uABG/CJdgRdKo04U2kzYaE9+OdqZuh52tjq71+VBbSsLwiDtbxe:cqG/CPgT0bYaEkOwMh52tjqESGbxe

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • SHARE BOT.exe (PID: 2480)
      • RtkBtManServ.exe (PID: 3108)
      • SHARE BOT.exe (PID: 3736)
      • RtkBtManServ.exe (PID: 3400)
    • Application was dropped or rewritten from another process

      • RtkBtManServ.exe (PID: 3108)
      • RtkBtManServ.exe (PID: 3400)
  • SUSPICIOUS

    • Checks supported languages

      • WinRAR.exe (PID: 2544)
      • SHARE BOT.exe (PID: 2480)
      • RtkBtManServ.exe (PID: 3108)
      • SHARE BOT.exe (PID: 3736)
      • RtkBtManServ.exe (PID: 3400)
    • Reads the computer name

      • SHARE BOT.exe (PID: 2480)
      • WinRAR.exe (PID: 2544)
      • RtkBtManServ.exe (PID: 3108)
      • SHARE BOT.exe (PID: 3736)
      • RtkBtManServ.exe (PID: 3400)
    • Executable content was dropped or overwritten

      • RtkBtManServ.exe (PID: 3108)
      • SHARE BOT.exe (PID: 2480)
      • SHARE BOT.exe (PID: 3736)
      • RtkBtManServ.exe (PID: 3400)
    • Drops a file with a compile date too recent

      • SHARE BOT.exe (PID: 2480)
      • RtkBtManServ.exe (PID: 3108)
      • SHARE BOT.exe (PID: 3736)
      • RtkBtManServ.exe (PID: 3400)
    • Reads Environment values

      • RtkBtManServ.exe (PID: 3108)
      • RtkBtManServ.exe (PID: 3400)
  • INFO

    • Manual execution by user

      • SHARE BOT.exe (PID: 2480)
      • SHARE BOT.exe (PID: 3736)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
5
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start drop and start winrar.exe no specs share bot.exe rtkbtmanserv.exe share bot.exe rtkbtmanserv.exe

Process information

PID
CMD
Path
Indicators
Parent process
2544"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Share_bot_10x_faster.rar"C:\Program Files\WinRAR\WinRAR.exeExplorer.EXE
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
2480"C:\Users\admin\Desktop\Share Bot\SHARE BOT.exe" C:\Users\admin\Desktop\Share Bot\SHARE BOT.exe
Explorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\share bot\share bot.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
3108"C:\Users\admin\AppData\Local\Temp\RtkBtManServ.exe" ZhXl39BlhP84+Y4kurA8wpehxxqA0X22IMYZ6Vpiqs6y4TKnDoePQdNDdYx1huNdtgaI9jNyM73ujn27oSYehMWJGjV6x28lrolZZNsgBNTlWLqelyXXo7eBVIjVdS4N5C/xmFDpl7B9DuOFrWRV9K5lOwqVdWPGkS0TIclpCtU=C:\Users\admin\AppData\Local\Temp\RtkBtManServ.exe
SHARE BOT.exe
User:
admin
Integrity Level:
MEDIUM
Description:
RtkBtManServ
Exit code:
3762504530
Version:
1.0.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\rtkbtmanserv.exe
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3736"C:\Users\admin\Desktop\Share Bot\SHARE BOT.exe" C:\Users\admin\Desktop\Share Bot\SHARE BOT.exe
Explorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\desktop\share bot\share bot.exe
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3400"C:\Users\admin\AppData\Local\Temp\RtkBtManServ.exe" ZhXl39BlhP84+Y4kurA8wpehxxqA0X22IMYZ6Vpiqs6y4TKnDoePQdNDdYx1huNdtgaI9jNyM73ujn27oSYehMWJGjV6x28lrolZZNsgBNTlWLqelyXXo7eBVIjVdS4N5C/xmFDpl7B9DuOFrWRV9K5lOwqVdWPGkS0TIclpCtU=C:\Users\admin\AppData\Local\Temp\RtkBtManServ.exe
SHARE BOT.exe
User:
admin
Integrity Level:
MEDIUM
Description:
RtkBtManServ
Version:
1.0.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\rtkbtmanserv.exe
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
2 655
Read events
2 618
Write events
37
Delete events
0

Modification events

(PID) Process:(2544) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2544) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2544) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16C\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2544) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\virtio_ivshmem_master_build.zip
(PID) Process:(2544) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(2544) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\Share_bot_10x_faster.rar
(PID) Process:(2544) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2544) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2544) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2544) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
14
Suspicious files
37
Text files
12
Unknown types
4

Dropped files

PID
Process
Filename
Type
2544WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2544.32134\Share Bot\SHARE BOT.exe
MD5:
SHA256:
2544WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2544.32134\Share Bot\Data\__pycache__\UserAgent.cpython-39.pycbinary
MD5:92C970D5CF931CFA5EFC2DC9C0AE979D
SHA256:25AA254474E139C88152A574D2FFDFF544B481A6EF5D4155E6422C8E5FDB6A85
2544WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2544.32134\Share Bot\Data\Lists.pytext
MD5:98AECAB5A5151D1FED591FBDEA1183ED
SHA256:8EEFC7DE835B2B35546AB96EB47ADC33F4D50306E82A88D9E716B6A7655609EE
2544WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2544.32134\Share Bot\Data\__pycache__\ScrapProxie.cpython-39.pycbinary
MD5:A927E90BEF3C1FE1153D449C3AFC5AEB
SHA256:8AC5876D7C7FE52AC0E94A2C44C372A528D7916E112DAC23547CC53F3993195E
2544WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2544.32134\Share Bot\Data\Proxies.txttext
MD5:9DD2311526B81AB41CD3DBBEB8B3657B
SHA256:D810FCA6DFF3C11E43724638D9A4758A20F70EDF863F8E4CAA10A685650360EC
2480SHARE BOT.exeC:\Users\admin\AppData\Local\Temp\whysosadtext
MD5:FC3C88C2080884D6C995D48E172FBC4F
SHA256:1637CE704A463BD3C91A38AA02D1030107670F91EE3F0DD4FA13D07A77BA2664
2544WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRa2544.32134\Share Bot\Data\__pycache__\Lists.cpython-39.pycbinary
MD5:2C424B2010531C3322A195079DEC7153
SHA256:CE173E38B1DDA1C86BF2BAD35C78E896EE81AF1FD3A978189C6F40C442A6F14C
3108RtkBtManServ.exeC:\Users\admin\AppData\Local\Temp\xwizard.cfgtext
MD5:AE8EED5A6B1470AEC0E7FECE8B0669EF
SHA256:3F6CA2BC068C8436044DAAB867F8FF8F75060048B29882CB2AC9FDEF1800DF9E
3108RtkBtManServ.exeC:\Users\admin\AppData\Local\Temp\winhlp32.exeexecutable
MD5:A776E68F497C996788B406A3DC5089EB
SHA256:071E26DDF5323DD9ED6671BCDE89DF73D78BAC2336070E6CB9E3E4B93BDE78D1
3108RtkBtManServ.exeC:\Users\admin\AppData\Local\Temp\snuvcdsm.exeexecutable
MD5:053778713819BEAB3DF309DF472787CD
SHA256:F999357A17E672E87FBED66D14BA2BEBD6FB04E058A1AAE0F0FDC49A797F58FE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info